Malicious
Malicious

d6c1e117cd4ed39c860aca612f9f7789

PowerShell
MD5: d6c1e117cd4ed39c860aca612f9f7789
Size: 1.41 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d6c1e117cd4ed39c860aca612f9f7789
Sha1 c283d7c70bc7f7090db497e3c413eb8d4d07a294
Sha256 efe6312c44c25aa49f246dd488b229556aba23b46a40ad7f1ea0dec09da03f03
Sha384 6526d85134eb6c6d6dec2906686ed8b235f812878f51be0ba0f0ad324a191edd7d6d9c2e0e237e9960a2b2a5a7c07153
Sha512 257e9c53601c44163052840a70f1112f364ed786de4c7beb2231989e88cc94ca0adf2a7a0794fc1e712499bdeeeb1bf12ad303f0df9b6557d8aad4e97115005c
SSDeep 12288:tg99l03ugnp9nn7Kitprciv8+77QbDrC3WllMg/Dr3Fcv9oku9bVRG6Yjczz3dYV:L
TLSH 5C6511523651FD7D029693B17E1646F0A86ACA40CEDF8556F24DCE88B14EC863AF93C3
d6c1e117cd4ed39c860aca612f9f7789
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
d6c1e117cd4ed39c860aca612f9f7789
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d6c1e117cd4ed39c860aca612f9f7789
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d6c1e117cd4ed39c860aca612f9f7789
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d6c1e117cd4ed39c860aca612f9f7789
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙