Malicious
Malicious

c342a551c2e8c1b03fc64824d9ec7820

PowerShell
MD5: c342a551c2e8c1b03fc64824d9ec7820
Size: 1.37 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c342a551c2e8c1b03fc64824d9ec7820
Sha1 b0c85effc6c19c7b592009b516aed5a638f604d5
Sha256 2bd8adca797c213f67d7aa7e94e09aed95ef539e8f409577fd2c258b2cb46fc7
Sha384 86ad61504f3f3bf466fd1481daeb0ce41ce51759ec45f9a4c7f3536f7358f0bba27812c7e5dc9c565a6403b00c257f60
Sha512 8f598614b68697e6005172d03652c6a0fe508ed4b35f4a1a3c7a0cd0b978a463a31f4b3fdd888a5bb7e86831b8a2ba3c9cd9f3f18541000c2f74559e4cb732f1
SSDeep 12288:nSmaQhmKYi0OV3uC+gAHbnRkcqtGjdHSZi2fnd2SEcNJ6zmOdYE+Uk20/P7FIQDG:S
TLSH 665521523651FD7D029693B16E1646F0A46ACA80CFDF8556F24DCE88B14EC863AF93C3
c342a551c2e8c1b03fc64824d9ec7820
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
c342a551c2e8c1b03fc64824d9ec7820
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
c342a551c2e8c1b03fc64824d9ec7820
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
c342a551c2e8c1b03fc64824d9ec7820
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
c342a551c2e8c1b03fc64824d9ec7820
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙