Malicious
Malicious

74c0f5b2501ecf2005eb7f531dc13e8d

PowerShell
MD5: 74c0f5b2501ecf2005eb7f531dc13e8d
Size: 1.69 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 74c0f5b2501ecf2005eb7f531dc13e8d
Sha1 5f1f7d3edc000884b0845b3ba62d38c9c3820777
Sha256 50e475897327e6b9637000d6dc9e1bcbc1196bf888dba8b08a1110adcf03e633
Sha384 c85bd529dc6cb20d5234f6861bfe571da4eb8028bf85c779c889e623988fe94c974ae5f67a0cf164d48ef1ccd16d00d1
Sha512 74703cc10d61a7e506005067dbc1e1a2af6b0b7ca6356c902230c4a4f9107e519ca281afddbe0e504b3658c8ddda4fb25dbfc966c2afe72b8f61312f6b28a93b
SSDeep 12288:85eG8LUB/EcQqQJz0IbqusnR/Que1v3H/2aovVNmqY0lgll2duaMZA0V4RLfaGQT:3
TLSH 7B75F0523951FD7D029693B56E1646F0A86ACA40CEDF8556F24DCE88B14DC833AFA3C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
74c0f5b2501ecf2005eb7f531dc13e8d
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
74c0f5b2501ecf2005eb7f531dc13e8d
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
74c0f5b2501ecf2005eb7f531dc13e8d
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
74c0f5b2501ecf2005eb7f531dc13e8d › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
74c0f5b2501ecf2005eb7f531dc13e8d › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙