Malicious
Malicious

b26ee0c83c1ad0663f79179f0bffbf19

PowerShell
MD5: b26ee0c83c1ad0663f79179f0bffbf19
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b26ee0c83c1ad0663f79179f0bffbf19
Sha1 24059a573df2aa210715f0b2d0d1842d55abb872
Sha256 f046d72b60bf5e3fcd977795eb533ffb23b14de1300eed699265a273d51cfa29
Sha384 205543b55a7074c29500af8801433542eb7e9583c338a94c1344dec4c01d83171bf80824646f07926e028cfa3d395a9e
Sha512 58ae8d4ae8306a65011b32825143cac244c7c0cf18ae45525acb7007a3e0db974544e70c56b64be2b93d567c309090f6e3b18de88f15424787c56393a3314db9
SSDeep 12288:jysrX3VUf5QE97rF0l4EGDVm/+r+sqgMRsx5xF2KFmlWkmM8iXWC4VP7074yBR1i:gcmv
TLSH DE6522523651FD7D029693B16E1646F0A46ACA40CFDF8556F24DCE88B14EC863AFA3C3
b26ee0c83c1ad0663f79179f0bffbf19
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
b26ee0c83c1ad0663f79179f0bffbf19
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b26ee0c83c1ad0663f79179f0bffbf19
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙