Malicious
Malicious

7f59f876650eb2ed0ba265b1bb0df1ab

PowerShell
MD5: 7f59f876650eb2ed0ba265b1bb0df1ab
Size: 1.6 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7f59f876650eb2ed0ba265b1bb0df1ab
Sha1 111506a90f39c9a47ae567d584af3f8b62121cf6
Sha256 7141b54f72e809ebe897625bf44ca2b2c49c0b97fb0824b659249a9842d1f67e
Sha384 022c05ccbec92239bf18ff4f33e33d6e30817718cea6b6ac260a9538a18f5c390bf05b79b6aa8b45cdfb15d99b9a9eb6
Sha512 d3ffd412c6fc5051039fb8b6425f268b7bc5e83d239b722d6fa0561ddac25ac0c3304434d0627466f4eb11674a1878ca1dd5708049bc6a2138d8927579bfb6e3
SSDeep 12288:yGKVK078hvMJ2oh+949IAybGfbq82Ifq4EnfXwN7TBeXOVEutU6BE7+TUd2T6pJx:T
TLSH DA75F0523651FD7D029693B16E1646F0A86ACA40CEDF8556F24DCE88B14DC873AF93C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7f59f876650eb2ed0ba265b1bb0df1ab
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7f59f876650eb2ed0ba265b1bb0df1ab
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7f59f876650eb2ed0ba265b1bb0df1ab
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7f59f876650eb2ed0ba265b1bb0df1ab › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7f59f876650eb2ed0ba265b1bb0df1ab › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙