Malicious
Malicious

8b25ea4a948d407ce8a15fab0870e68e

PowerShell
MD5: 8b25ea4a948d407ce8a15fab0870e68e
Size: 1.4 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8b25ea4a948d407ce8a15fab0870e68e
Sha1 78ee0cf37ad8be292489c6046263e4b7b7de6742
Sha256 398c56fb3a7ccf93374eeb367dae6fdaa1e49404c7fa59748bf16d87af39ad4d
Sha384 844664b19c41918feec6c38bbacc06e6d008077a07a9ca36f9508aea683ffd73641b22bedc4516d7506889b8bcf49350
Sha512 8b43a5bc80cdd65824dd17ea944256f1071ebb0419a678b029115d6afc96c91329a800603595f5e537ddedcd5e68b65dfa9d7d4ef566391f486b8ac72e29f6f0
SSDeep 12288:d7NccoI1m8cyBSG5AMY4r+9eZwNerqobZI8nBruWaHBf9SuVa03lW+pTK+yIQxU2:LZ
TLSH 1C5510523651FD7D029693B16E1646F0A46ACA40CEDF8556F24DCE88B14EC873AFA3C3
8b25ea4a948d407ce8a15fab0870e68e
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
8b25ea4a948d407ce8a15fab0870e68e
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8b25ea4a948d407ce8a15fab0870e68e › [PowerShell Command] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8b25ea4a948d407ce8a15fab0870e68e
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8b25ea4a948d407ce8a15fab0870e68e
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙