Malicious
Malicious

8fee84d6ea90fa8aa56838964500baa7

PowerShell
MD5: 8fee84d6ea90fa8aa56838964500baa7
Size: 1.37 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8fee84d6ea90fa8aa56838964500baa7
Sha1 369ea4e0b6bd1386ad88ec21608da7d2f8428720
Sha256 9f43563f43983d9e9a889b73290f3c0f2a0b61bab252a4889ef0df3df18aad38
Sha384 70ea9ffaaa2830b64274041966b1f7bec014c1af6f624e6079bc71bef892165c535db97ce3c50e27e305e6ce6d999b42
Sha512 9ec96548f05606bd799aec4470077a5d3384dd02026f4ec180deee8c8816093fee45fd0f924000f170b5f15e8e7b9040178349028b44540bc4d2ebf18d1b6094
SSDeep 12288:qQe//bUggYpzK7nNVCfZFkskvF6GmSaE1KbuzQL17cdZl/LmDWXOBCz9YaSj33Qs:M
TLSH C85512523A51FD7D029693B16E1646F0A46ACA40CFDF8556F24DCE88B14EC863AF93C3
8fee84d6ea90fa8aa56838964500baa7
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
8fee84d6ea90fa8aa56838964500baa7
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8fee84d6ea90fa8aa56838964500baa7 › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8fee84d6ea90fa8aa56838964500baa7
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
8fee84d6ea90fa8aa56838964500baa7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙