Malicious
PowerShell
MD5: 71ffbfe6d1391315f1e35401abc62830
Size: 22.91 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 71ffbfe6d1391315f1e35401abc62830 |
| Sha1 | 5a7ffae4eccc26171194895db4f86fcaa28255c5 |
| Sha256 | 5e9826121163fc56a55c1e0b78aa80aac97c1e83e09b45f744bd3de5b0adc9fe |
| Sha384 | 2da94c321619debb27ce991178ca190d81b6f22ad1f4310be987adfca9ca44e8776a7168760934308ce1e6c91c068482 |
| Sha512 | e736576f6ef1040f070b5a11bef120d70ee0466d27afdc8695c701b6fd990044a65fff4e4a0fbad6783a5fb2651324e74291ca53d35c97f12f62493d1ea19dae |
| SSDeep | 384:giYTQT4tPKm++ZlzsDCaBkx3GrLcPgLcKTBvPbNP7NPKXPHXPpXPPXPk+qPPP4Px:OTQT4tN/3sVy3IcoAKJTNDNiXvXRX3XH |
| TLSH | 16A20C607F5292040EA3C0553A76A5A5D329353B707AAC88BECCC7D5DF721E692FC13A |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential