File classification
Confirmed malware sample
Classification is bounded to named stored sources.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type sha256 · source intel_report_ingest
MENTIONED — 2 reports, unverified
Malware file investigation
MalwareBazaar reported this ps1 sample as confirmed malware. No malware family is established. 2 distinct sources and 2 verified alternate digests are available. The hash identifies file bytes; it does not prove the file executed in any environment.
File classification
Confirmed malware sample
Classification is bounded to named stored sources.
Malware family
No family attribution
No family name is asserted from generic tags.
File profile
SHA-256 · ps1
No bounded behavior category is available from stored tags.
Source corroboration
2 distinct connectors
57 polling citations are shown separately and not treated as independent evidence.
Related evidence
2 same-file digest variants · 1 report mention
Only persisted same-file edges, YARA matches, and exact report mentions count here; generic file-type co-tags are excluded.
Observation window
2026-07-31 → 2026-08-20
These are first and last local feed observations, not file creation or execution times.
Findings stay bounded to named sources and observable infrastructure.
Neighborhood topology. Open the graph for interactive pivots.
Loading connected indicators, reports and entities.
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Exact hash match in locally ingested report title/body
Read the report for scope and publication date before applying its conclusions to this sample.