Malicious
Malicious

b34069e88b207ef1cbdcfb312c1ad719

PowerShell
MD5: b34069e88b207ef1cbdcfb312c1ad719
Size: 1.44 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b34069e88b207ef1cbdcfb312c1ad719
Sha1 e85f215f90a4f697285376a9ce3511cf01a5cc0a
Sha256 238910a299afddeb66018bd8d0ee63480e73f6e1a090cb75a01e85be6c4c385c
Sha384 cf7745389110546a709d0d6f7d80968437b02f813b5150fd2d33a04215a6af934cff5e024bac57165100c10b84cf8600
Sha512 c5ddbd1a5ddbe3d7f869d32df1dd7d270ed147b2eef08f3feb64a08a877104269750ca5af808b51a3b9c3ff4e18d538d23a02a9d928d294054b02b6b736641d3
SSDeep 12288:RwuXsd3cXV+3MoLMS8RH9mNIorA0WI9G3+mJH2WDP59Rd28KqVsPEG1qnhfR6m0E:n
TLSH 046511523551FD7D029693B16E1646F0A86ACA40CFDF8556F24DCE88B14EC863AFA3C3
b34069e88b207ef1cbdcfb312c1ad719
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
b34069e88b207ef1cbdcfb312c1ad719
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b34069e88b207ef1cbdcfb312c1ad719
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b34069e88b207ef1cbdcfb312c1ad719
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b34069e88b207ef1cbdcfb312c1ad719
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙