Malicious
Malicious

d9da817b7774dfb0e079dba87503b9ad

PowerShell
MD5: d9da817b7774dfb0e079dba87503b9ad
Size: 85.78 KB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d9da817b7774dfb0e079dba87503b9ad
Sha1 045a3b83991b954b77405cb0287322bb48dba6f8
Sha256 8209bb5223a3afbedd0d3f3d689baba884b9a217ae238bb8b81a67034d51742f
Sha384 b27b48c2a63fc152579ce3ce4f2c302dcab2ef84d2a8cc3112a4510407e16ac1027bd04020aa953d997012075341d7ca
Sha512 afc2e6774881d99a17e85f93a8339509a908eddda37e374f5a5235d82249c26e8826545ca022aff1e7fd8518147f8f2deda8c4d52cf7202add25f02ef773d0bf
SSDeep 768:dpoMqLDDgfLmhiiJLF4DzMpeeWx2SSdwtLOTk:dpFCIiiZYpe1Tz
TLSH 4783B719FB311BA83094F4FC89A7702C6672889FC66CD175687F37344AE52E068B4D9B
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.007>scr:js~T1027~T1059.001~T1059.007~T1105
Shape scr:ps1>scr:js
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d9da817b7774dfb0e079dba87503b9ad › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d9da817b7774dfb0e079dba87503b9ad › [PowerShell Command] › [Deobfuscated PS]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
d9da817b7774dfb0e079dba87503b9ad › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙