Malicious
Malicious

f9de04a40b98f268fc2e52cb5ac7d415

PowerShell
MD5: f9de04a40b98f268fc2e52cb5ac7d415
Size: 1.42 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f9de04a40b98f268fc2e52cb5ac7d415
Sha1 88bd700ffdb40c98956766b2b6052679d244eb21
Sha256 b38ceef4eb26aa6d2ccc3e9ef19996830d91b16261cf04768842f028f15e1eeb
Sha384 5bf665a4095c6ce26c7fd46a28ec186b6598abededb1cdd53a413fce02b974809986b919db84974d877ceb085eafbdf1
Sha512 515589e1bdbf208b219554d24f700921877fca28db0f24e8525ddb0cb512fdf572ca7ab73f83d8f772ba475ff64db9bc46beaa8f090cb2ceb1818edbc08cc6ce
SSDeep 12288:5xfe7fdtalBmONbTm7d7Ip+Zj9DWVoxYwNikuC541HI+fqmC+eUpi0Up8sbi5swo:0
TLSH D36510523651FD7D029693B16E1646F0A46ACA80CFDF8556F24DCE8CA14EC863AF93C3
f9de04a40b98f268fc2e52cb5ac7d415
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
f9de04a40b98f268fc2e52cb5ac7d415
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
f9de04a40b98f268fc2e52cb5ac7d415
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
f9de04a40b98f268fc2e52cb5ac7d415
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
f9de04a40b98f268fc2e52cb5ac7d415
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙