Malicious
31bf1196a86f2e6248002115194bb71a
PowerShell
MD5: 31bf1196a86f2e6248002115194bb71a
Size: 1.36 MB
application/x-powershell
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 31bf1196a86f2e6248002115194bb71a |
| Sha1 | 6cc1ff8b0667f03b36e0f92c599e70a79b282350 |
| Sha256 | 227eed67bc0341815bfc553e1757fe1cd257d9e1fca3a9cdd13380096d0165ec |
| Sha384 | d86dd827407a759546cd06d636baafd5dda789ec15a125b8320d12bc70a71b76a0cfcb6f703333abb51ec8e69e163f04 |
| Sha512 | f0de8560b984ba085c1e8c7d7298687698ddaad453c20a74d6179b22b2686311249b45ecafa03b65a6d78842a470eb3696f6681de3a11ce7a9cf50f8cf9511b9 |
| SSDeep | 12288:1hGsBz8nDm7Y1EIGrNtZ34jqODvL0hnTlgd8qbQmL2d3702/urj7ETRfzD04wWzb:z |
| TLSH | 145522523A51FD7D029793B16E1646F0A47ACA40CEDF8556F24DCE88A14EC863AF93C3 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:ps1~T1059.001~T1105
Shape
scr:ps1
malicious
1 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
31bf1196a86f2e6248002115194bb71a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.