MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0dd457b97dc92cdd6a4591af53eeb4c9ce0acdf806681d69ecb36c9cdd535e53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0dd457b97dc92cdd6a4591af53eeb4c9ce0acdf806681d69ecb36c9cdd535e53
SHA3-384 hash: 0dd410f66da8181b1176afbe0f05c22228c55e96ab28121baa32676033307e9ada270c3db0f2e0f5751d99a6b1813cbb
SHA1 hash: 7297add5893f4f28658796faf7e23dff0154091c
MD5 hash: f85a47cfa8aa9795f9b8a37ebb29925c
humanhash: king-speaker-venus-connecticut
File name:ps1.ps1
Download: download sample
File size:2'732 bytes
First seen:2026-06-18 06:05:05 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:NoTy7ytT7WZuWLxUM2WeYkE54ihLcn0SRRB8kURosLN/YNg3Ul:NO7fWJ7pN5x2/qkU2hN8Ul
TLSH T1585164B4830A1FBED9CD0888D3823247D0FB3C8876D29D467B35A9521D6F2F45AA08D9
Magika powershell
Reporter JAMESWT_WT
Tags:ps1 purmed-ro

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
70%
Tags:
malware
Gathering data
Threat name:
Script-PowerShell.Trojan.GuLoader
Status:
Malicious
First seen:
2026-06-18 06:03:06 UTC
File Type:
Text (AutoIt)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments