🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0838fa819961d0a56be064ebb4bc6542be2338e17937ec8ca1cc646acb75833a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureHVNC


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0838fa819961d0a56be064ebb4bc6542be2338e17937ec8ca1cc646acb75833a
SHA3-384 hash: 3a7f32aa8cf007881fe2b86f7d9f94a1b90e843cf3db02fbb412bf7c7e7dd21e5377d456ecefd71c412b40a4f356c8bc
SHA1 hash: fc2e67fbceffdcc7938c7fe569992dff048f6f84
MD5 hash: 663dbe4c5a60239a627aea6b1e09dd36
humanhash: single-comet-jig-indigo
File name:ps.ps1
Download: download sample
Signature PureHVNC
File size:49 bytes
First seen:2026-04-24 13:02:58 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:VSJJFIqF1F65IFR8ZKMn:s8qF1F8oMn
TLSH TNULL
Magika batch
Reporter JAMESWT_WT
Tags:booking halfmillion-iq-com nisuwyyyqsafdas-com ps1 PureHVNC

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
trojan agent shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated powershell soft-404
Verdict:
Malicious
File Type:
ps1
First seen:
2026-04-24T10:51:00Z UTC
Last seen:
2026-04-24T13:55:00Z UTC
Hits:
~100
Detections:
Trojan.PowerShell.Cobalt.sb Trojan.PowerShell.Agent.sb Trojan-Dropper.Win32.Injector.sb Trojan.Win32.Agent.sb Trojan.PowerShell.Persik.sbr Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Coins.sb Trojan-PSW.MSIL.Stealer.sb Trojan-Spy.Agent.HTTP.C&C HEUR:Trojan-PSW.MSIL.Coins.gen Backdoor.Win32.Androm.sb Backdoor.Agent.HTTP.C&C Trojan.Win64.Agent.sb NetTool.PowerShellGet.HTTP.C&C NetTool.PowerShellUA.HTTP.C&C
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments