Malicious
Malicious

71ffbfe6d1391315f1e35401abc62830

Share on LinkedIn
Print
PowerShell
MD5: 71ffbfe6d1391315f1e35401abc62830
Size: 22.91 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 71ffbfe6d1391315f1e35401abc62830
Sha1 5a7ffae4eccc26171194895db4f86fcaa28255c5
Sha256 5e9826121163fc56a55c1e0b78aa80aac97c1e83e09b45f744bd3de5b0adc9fe
Sha384 2da94c321619debb27ce991178ca190d81b6f22ad1f4310be987adfca9ca44e8776a7168760934308ce1e6c91c068482
Sha512 e736576f6ef1040f070b5a11bef120d70ee0466d27afdc8695c701b6fd990044a65fff4e4a0fbad6783a5fb2651324e74291ca53d35c97f12f62493d1ea19dae
SSDeep 384:giYTQT4tPKm++ZlzsDCaBkx3GrLcPgLcKTBvPbNP7NPKXPHXPpXPPXPk+qPPP4Px:OTQT4tN/3sVy3IcoAKJTNDNiXvXRX3XH
TLSH 16A20C607F5292040EA3C0553A76A5A5D329353B707AAC88BECCC7D5DF721E692FC13A
71ffbfe6d1391315f1e35401abc62830
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙