Malicious
Malicious

8a9294887013b416cdec0309c5489ded

PowerShell
MD5: 8a9294887013b416cdec0309c5489ded
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8a9294887013b416cdec0309c5489ded
Sha1 1fa37d65587efb6a98e381038d5db02e1dcd99ec
Sha256 c9b1a9c171ca07c8fcc9154921305c24fef69644497f30db163e5700700f7fcb
Sha384 4c9be3f82514f9eab8478ca6b7b232e9c722784c7171a260030669c7c03e226927d0758bf710d2b6471498ee37c658f0
Sha512 542af483c7ad8ee7fdb7c6b89a457189e0d4e4f55ec5c1de6679dd71612ec0edb830cd3fd5393649183a0246f616680ebba1a2753b55b4158715aae2745ba53f
SSDeep 12288:GI62M0oZsaSwYOi5Q46FsyTJzTG+AXjW9DN+ibBM9u7riby2z3SdsFMnCIePgILq:U
TLSH 115521523651FD7D029693B17E1646F0A46ACA40CFDF8556F24DCE88A14EC863AFA3C3
8a9294887013b416cdec0309c5489ded
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
8a9294887013b416cdec0309c5489ded
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8a9294887013b416cdec0309c5489ded › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8a9294887013b416cdec0309c5489ded
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8a9294887013b416cdec0309c5489ded
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙