Malicious
Malicious

7f59f876650eb2ed0ba265b1bb0df1ab

Share on LinkedIn
Print
PowerShell
MD5: 7f59f876650eb2ed0ba265b1bb0df1ab
Size: 1.6 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7f59f876650eb2ed0ba265b1bb0df1ab
Sha1 111506a90f39c9a47ae567d584af3f8b62121cf6
Sha256 7141b54f72e809ebe897625bf44ca2b2c49c0b97fb0824b659249a9842d1f67e
Sha384 022c05ccbec92239bf18ff4f33e33d6e30817718cea6b6ac260a9538a18f5c390bf05b79b6aa8b45cdfb15d99b9a9eb6
Sha512 d3ffd412c6fc5051039fb8b6425f268b7bc5e83d239b722d6fa0561ddac25ac0c3304434d0627466f4eb11674a1878ca1dd5708049bc6a2138d8927579bfb6e3
SSDeep 12288:yGKVK078hvMJ2oh+949IAybGfbq82Ifq4EnfXwN7TBeXOVEutU6BE7+TUd2T6pJx:T
TLSH DA75F0523651FD7D029693B16E1646F0A86ACA40CEDF8556F24DCE88B14DC873AF93C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105>pe:dll>pe:rsrc>bin
Shape scr:ps1>pe:dll>pe:rsrc>bin
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙