Malicious
6b6f4b3c73018240db656a102e821f45
PowerShell
MD5: 6b6f4b3c73018240db656a102e821f45
Size: 1.4 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 6b6f4b3c73018240db656a102e821f45 |
| Sha1 | 1b0cc93b725c907bd75cb342c55401cf60870116 |
| Sha256 | af87f7f4cdf75719fd9167b36a5f6ee0f3697b682fddcecf26a63d69fa3dc807 |
| Sha384 | 989a1b2109b30442d4cb2cf9543d662b0659879d43758918ba6b67cd4daa5423ea5798fb0078b7793c5d7268cf9209e0 |
| Sha512 | 265de37d8022d79ed33192374665e8930d3ac647e6d1077751551832662f63766892ffe64cd76ab8e6526614981d8a9d824456253a507dcaa8f110f2192fadf6 |
| SSDeep | 12288:Zs4edUv5GlqiJ0ZeMia6WgQkJrd1JRqzXJJeQ1adVJYy2+EhjAWx+1h/eMHU2uDj:J |
| TLSH | 8F5511523651F97D029793B57E1646F0A46ACA40CEDF8556F24DCE8CA14EC823AFA3C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6b6f4b3c73018240db656a102e821f45
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.