Suspicious
Suspect

b7ccc42d9adc285f91ef92fbedcc8751

PowerShell
MD5: b7ccc42d9adc285f91ef92fbedcc8751
Size: 5.15 KB
application/x-powershell

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b7ccc42d9adc285f91ef92fbedcc8751
Sha1 2c46a5a1386bdcc67bf90c00fca2d8b8f807e729
Sha256 c033ca5d8bc4832a20051b36ccce6bd4c96c7a0de25d843d4d920b994c258093
Sha384 868252af494839896d9db1212b9d7eebf5669a63b4a548b8d3421b485a583eed457cbf5915d157ebf8a7e0fcc37dc0c1
Sha512 857e3eb378924a6a9f72bfe3625125d01663e132a9c52e9312299bfc75eeac7b9eea6f4b3f053f2e49ce3a961b937ace458b94e75acd4968561d651cc0fec7e6
SSDeep 96:xbmXpvJSKVW2QiP9F6/qToaB7vg1sX13lkEhnrW41w1T0JRNYYJ5mZt:xepv4uW2QiSyToaNvdNlkKnM0JjNK
TLSH 15B1B83AB362AE5343C239A5F15536DF6B2F112F818D42C4BA8CC8AD677583DC7690C8
[Base64-Block]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
technique1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Base64-Block]
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b7ccc42d9adc285f91ef92fbedcc8751
URL in PowerShell #2 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
b7ccc42d9adc285f91ef92fbedcc8751
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b7ccc42d9adc285f91ef92fbedcc8751
URL in PowerShell #4 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b7ccc42d9adc285f91ef92fbedcc8751
URL in PowerShell #5 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
b7ccc42d9adc285f91ef92fbedcc8751
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙