Malicious
Malicious

e9408661d8eba029604f78bd85ef2fb1

PowerShell
MD5: e9408661d8eba029604f78bd85ef2fb1
Size: 1.43 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e9408661d8eba029604f78bd85ef2fb1
Sha1 c368ef880d25f501d06c112627d4ded0b40627d6
Sha256 7531b14b11b875ad6b1b3ba55519cac31b352ffea658f7827787053d55def68f
Sha384 6ac162ac72c7e55fbae051d698540bf4356707d60b6507b9e3e41712dcb8502ea6575a19b45d67fb0c09121db25f9594
Sha512 2546e98efbd8ac27eef9d1441db192ca48881d9f36245b5c0197bc4725a3a4eda3937339acd7150e70bcc5d4a2ce598745f679a8b3073c4846731aabf67f0372
SSDeep 12288:vdFOoA8GG9U29EpMfxeWeNxn6XMBj3AO8xJi/h58S6CfftySHOor9t+T9ylT/fXw:Rf
TLSH 086511523651FD7D029693B17E1646F0A46ACA80CEDF8556F24DCE88B14EC863AF93C3
e9408661d8eba029604f78bd85ef2fb1
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
e9408661d8eba029604f78bd85ef2fb1
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
e9408661d8eba029604f78bd85ef2fb1
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
e9408661d8eba029604f78bd85ef2fb1
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
e9408661d8eba029604f78bd85ef2fb1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙