Malicious
Malicious

bf97f9d5d86c685d66edd8e2aad67074

PowerShell
MD5: bf97f9d5d86c685d66edd8e2aad67074
Size: 1.39 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bf97f9d5d86c685d66edd8e2aad67074
Sha1 282a398c678f20f41a80c7456ce1f62ecddbe026
Sha256 4efdab323a257f12f3478cc1a5bf2448ef2e6eb0e57fed09ee9824b680d9e829
Sha384 ab357fb8d85920e1b57c190af5035de4b9d6ed99de1bf948e13cc89a15204bad216077f13b7cfe60cc666e39e7348d97
Sha512 63f6976af3bd7c2301f1159b83deceda959a6bde530c2db1872ee27703e9255d252dc258650cf16c75ec4b57a1620e1a4dbfaaccbccc5ea21dc4a5f27828154f
SSDeep 12288:gRWvDEd5SclB8RyEJZ/nfyZ7pp7bqUhiC9WpVb6trfEsw/wdkbuaN0Mb9y1iGyrN:f
TLSH 035521523A51FD7D029793B17E1646F0A46ACA40CEDF8556F24DCE88A14ED823AF93C3
bf97f9d5d86c685d66edd8e2aad67074
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
bf97f9d5d86c685d66edd8e2aad67074
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bf97f9d5d86c685d66edd8e2aad67074
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙