Malicious
31b0403df3d507f6e8bb233d2e1c0264
PowerShell
MD5: 31b0403df3d507f6e8bb233d2e1c0264
Size: 5.49 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 31b0403df3d507f6e8bb233d2e1c0264 |
| Sha1 | c105439ff996a6667fdbfdb5c2f8d991b931dc3a |
| Sha256 | c18dc03e19a7a80431fc2a836500bd97d9b2d6f65d1193735a4a148c4fa1e272 |
| Sha384 | afdd2d1d2e0a32ec6c262604c512b30ebb0dec49d32bb058574d3079b04055279611c04cb673fca030ca1d44a81da684 |
| Sha512 | 0015ef7627494041854dfdada614600b717b436ad8df22ae8ebaa6ee4fe54fb6749f61e1a020a2a1da05f3616b69a4ef7ad12021ae286e78e0a34200b98f58c8 |
| SSDeep | 24576:OweW67lvSLm4pNfRl3TyROs4USJ9VZ2qwrdKPoeXD2isa3H82RK+kbDnvmmsW/LX:fZziWGKiK+B |
| TLSH | D6468F616E5859F5EF8C2A0E90AE6F1D87F042176A33706BFB41DF04BDDA241864B21F |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1027~T1059.001
Shape
scr:ps1
malicious
1 nodes
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
" " +huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
"
"huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS]
Deobfuscated PowerShell
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS]
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"+"
"huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
reads huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS]
Deobfuscated PowerShell
UNKNWOWNmalicious
[Unmanhuhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
" " +huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell
UNKNWOWNmalicious
"
"huhuhuhuhuhuhuhuhuhuhu
31b0403df3d507f6e8bb233d2e1c0264 › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.