Malicious
Malicious

6bdde0c83d3f5cbe9ca1a372580e1de3

PowerShell
MD5: 6bdde0c83d3f5cbe9ca1a372580e1de3
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6bdde0c83d3f5cbe9ca1a372580e1de3
Sha1 f0b9ec5c9631be242efe5dff9c3ec08c408ada62
Sha256 3e7fd1a1346d72e2579ff5e0d6378af1f92be197ff27373ba53e25b622453e66
Sha384 d11c894993b8ab3853cfb27fcaa23c4945675bdfa6635c43d3af4954996d9336c519df23e89bd85050789209aa17da6d
Sha512 96fbd408b1247861b28e46896f9d6de0ded85f82e6855c96df52d0edffaa5211a8fe23e383c05178dd07d0a5c920793b1cc3cd523e816bb0e8561140c25ef4db
SSDeep 12288:llpNxnt8I1inK29V5D20QWf27sd4cW5NsvvnwJBxx1YDYSselojlkvR/Vi54LVSQ:q
TLSH B05511523651FD7D029693B16E1646F0A46ACA40CFDF8556F24DCE88B14EC863AFA3C3
6bdde0c83d3f5cbe9ca1a372580e1de3
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
6bdde0c83d3f5cbe9ca1a372580e1de3
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙