Malicious
6bdde0c83d3f5cbe9ca1a372580e1de3
PowerShell
MD5: 6bdde0c83d3f5cbe9ca1a372580e1de3
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 6bdde0c83d3f5cbe9ca1a372580e1de3 |
| Sha1 | f0b9ec5c9631be242efe5dff9c3ec08c408ada62 |
| Sha256 | 3e7fd1a1346d72e2579ff5e0d6378af1f92be197ff27373ba53e25b622453e66 |
| Sha384 | d11c894993b8ab3853cfb27fcaa23c4945675bdfa6635c43d3af4954996d9336c519df23e89bd85050789209aa17da6d |
| Sha512 | 96fbd408b1247861b28e46896f9d6de0ded85f82e6855c96df52d0edffaa5211a8fe23e383c05178dd07d0a5c920793b1cc3cd523e816bb0e8561140c25ef4db |
| SSDeep | 12288:llpNxnt8I1inK29V5D20QWf27sd4cW5NsvvnwJBxx1YDYSselojlkvR/Vi54LVSQ:q |
| TLSH | B05511523651FD7D029693B16E1646F0A46ACA40CFDF8556F24DCE88B14EC863AFA3C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
6bdde0c83d3f5cbe9ca1a372580e1de3
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.