Malicious
Malicious

eef7e93393686990aee314df98fb161d

PowerShell
MD5: eef7e93393686990aee314df98fb161d
Size: 1.46 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 eef7e93393686990aee314df98fb161d
Sha1 f6627878357898caee0472759911e4793d823ceb
Sha256 7a7174b0819123879bd36fea614d9fcb23747c0eb2952f140d903cb1926ff2f5
Sha384 b96acb32abb2090ca2aa0c69c12e7ccf70b8d8762de0010bedff536388c017a26a767cdf4d14ff19d24795db5a64f0ac
Sha512 81f595568250caef227a534737880285c702b17f1331471e07b945c9147865b1fd3f3f34a2b7eae8c54dc9f01d75027cda0c22d638579500894c214050fb81a1
SSDeep 12288:i87upPrMPtnvQMuqBuSH6Y12BEcEME9Bt2cHWBDbc7eJaR/61DkcpaXty4mcObco:W
TLSH 8F6521523A51FD7D029693B16E1646F0A46ACA40CEDF8556F24DCE8CB14EC863AF93C3
eef7e93393686990aee314df98fb161d
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
eef7e93393686990aee314df98fb161d
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
eef7e93393686990aee314df98fb161d › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
eef7e93393686990aee314df98fb161d
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
eef7e93393686990aee314df98fb161d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙