Malicious
b26ee0c83c1ad0663f79179f0bffbf19
PowerShell
MD5: b26ee0c83c1ad0663f79179f0bffbf19
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b26ee0c83c1ad0663f79179f0bffbf19 |
| Sha1 | 24059a573df2aa210715f0b2d0d1842d55abb872 |
| Sha256 | f046d72b60bf5e3fcd977795eb533ffb23b14de1300eed699265a273d51cfa29 |
| Sha384 | 205543b55a7074c29500af8801433542eb7e9583c338a94c1344dec4c01d83171bf80824646f07926e028cfa3d395a9e |
| Sha512 | 58ae8d4ae8306a65011b32825143cac244c7c0cf18ae45525acb7007a3e0db974544e70c56b64be2b93d567c309090f6e3b18de88f15424787c56393a3314db9 |
| SSDeep | 12288:jysrX3VUf5QE97rF0l4EGDVm/+r+sqgMRsx5xF2KFmlWkmM8iXWC4VP7074yBR1i:gcmv |
| TLSH | DE6522523651FD7D029693B16E1646F0A46ACA40CFDF8556F24DCE88B14EC863AFA3C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.