Malicious
Malicious

b50d7a72d109141f4e3cc1dfb7d7fcb8

PowerShell
MD5: b50d7a72d109141f4e3cc1dfb7d7fcb8
Size: 1.34 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b50d7a72d109141f4e3cc1dfb7d7fcb8
Sha1 d0b6b6dcb7db68f52204d29bfe046556487429ae
Sha256 ad0e92ef0a0e5be102819c951ddd0adcd668cf2592521bc170fd2f639cca621b
Sha384 819a987a762e60aa5346b40145be6bcd7a218bc5429447ffba29f00331f9b29c61d16fcf6852385284e67b0afb800e59
Sha512 41b206d1275326ae0454616351a43809038916556ca0b32e75ea752fb3a9e69d57f3ef1327e632a91bf8f194f0f96b9d33af0302601bc1d18ca3686d3003072d
SSDeep 12288:w2LesdxBYnsZCSOZz6zybl4zIc97UwW0cINjGMrjVk2qDtpUPgD0ByIAzfZ0ULKl:z
TLSH F95511523651FD7D029693B16E1646F0A46ACA40CFDB8556F24DCE8CB14EC863AFA3C3
b50d7a72d109141f4e3cc1dfb7d7fcb8
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
b50d7a72d109141f4e3cc1dfb7d7fcb8
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b50d7a72d109141f4e3cc1dfb7d7fcb8
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b50d7a72d109141f4e3cc1dfb7d7fcb8
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b50d7a72d109141f4e3cc1dfb7d7fcb8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙