MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ea17807b709db137a996ba1d021f86e89a1a8257d5bb04494caa78049d4c75d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0ea17807b709db137a996ba1d021f86e89a1a8257d5bb04494caa78049d4c75d
SHA3-384 hash: 72a0dae47d544c1dd078ba3fdeeecaedf3abf9bf0ccebb2c96246438b9b147e3084c9f2d47ddc4c4292f2e677ead37db
SHA1 hash: 71b5410487f2c84a1fd842f4642d4b3afed2675f
MD5 hash: 5781d42fb63c4eaf5676b19fcdb155dd
humanhash: oranges-foxtrot-lemon-low
File name:ps.ps1
Download: download sample
File size:74 bytes
First seen:2026-07-23 13:13:48 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:VSJJFIGFhPPFyLX3LD100qkc/0yOGUn:s8GFhP4LX7D10Ac/0zn
TLSH T18FA022220C30020C8A02208AEE30CBF0CE2A0C008AAFECB23808B2CE0FF0F30E030000
Magika txt
Reporter JAMESWT_WT
Tags:completstep-com ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated powershell
Verdict:
Malicious
File Type:
ps1
First seen:
2026-07-23T11:27:00Z UTC
Last seen:
2026-07-23T19:38:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Malware Config
Dropper Extraction:
http://135.181.127.216/dl-callback/94rwryy7-6vyvayjx-hw6uuu6v-6dgkme2r/Safe-1.zip/bbf914db4b63b3d2f90da472e53f5beb
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments