Malicious
Malicious

31bf1196a86f2e6248002115194bb71a

PowerShell
MD5: 31bf1196a86f2e6248002115194bb71a
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 31bf1196a86f2e6248002115194bb71a
Sha1 6cc1ff8b0667f03b36e0f92c599e70a79b282350
Sha256 227eed67bc0341815bfc553e1757fe1cd257d9e1fca3a9cdd13380096d0165ec
Sha384 d86dd827407a759546cd06d636baafd5dda789ec15a125b8320d12bc70a71b76a0cfcb6f703333abb51ec8e69e163f04
Sha512 f0de8560b984ba085c1e8c7d7298687698ddaad453c20a74d6179b22b2686311249b45ecafa03b65a6d78842a470eb3696f6681de3a11ce7a9cf50f8cf9511b9
SSDeep 12288:1hGsBz8nDm7Y1EIGrNtZ34jqODvL0hnTlgd8qbQmL2d3702/urj7ETRfzD04wWzb:z
TLSH 145522523A51FD7D029793B16E1646F0A47ACA40CEDF8556F24DCE88A14EC863AF93C3
31bf1196a86f2e6248002115194bb71a
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:ps1~T1059.001~T1105
Shape scr:ps1
malicious 1 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
31bf1196a86f2e6248002115194bb71a
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙