Malicious
bf97f9d5d86c685d66edd8e2aad67074
PowerShell
MD5: bf97f9d5d86c685d66edd8e2aad67074
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | bf97f9d5d86c685d66edd8e2aad67074 |
| Sha1 | 282a398c678f20f41a80c7456ce1f62ecddbe026 |
| Sha256 | 4efdab323a257f12f3478cc1a5bf2448ef2e6eb0e57fed09ee9824b680d9e829 |
| Sha384 | ab357fb8d85920e1b57c190af5035de4b9d6ed99de1bf948e13cc89a15204bad216077f13b7cfe60cc666e39e7348d97 |
| Sha512 | 63f6976af3bd7c2301f1159b83deceda959a6bde530c2db1872ee27703e9255d252dc258650cf16c75ec4b57a1620e1a4dbfaaccbccc5ea21dc4a5f27828154f |
| SSDeep | 12288:gRWvDEd5SclB8RyEJZ/nfyZ7pp7bqUhiC9WpVb6trfEsw/wdkbuaN0Mb9y1iGyrN:f |
| TLSH | 035521523A51FD7D029793B17E1646F0A46ACA40CEDF8556F24DCE88A14ED823AF93C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.