🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12d20fc0045eb4aefbeef0498e9c787c7ddcbeea433f99d9430e995a23f63b58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: 12d20fc0045eb4aefbeef0498e9c787c7ddcbeea433f99d9430e995a23f63b58
SHA3-384 hash: 6cec2c4785ad1c55fc1156c6e314a97d7a1a4efe66fda2e3df8ac01e6821c5284177536b196ee8ba833a7087d5ef981e
SHA1 hash: 83d10f96dd98a9350b399a3b7c99cc29c21c8343
MD5 hash: 48e757c227bdc2b5402038f4e6e5f036
humanhash: freddie-robert-sixteen-east
File name:seo.ps1
Download: download sample
File size:77'685 bytes
First seen:2026-04-29 17:15:20 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 768:bQx2uDehSMCnONhlJMKe0FIiBJt7LsIXIQHxg2aU8O8Av4pruUYfkdc4GsQh:eF8hlJNzyqxg2aU8OX4prupbsQh
TLSH T15A7302D717D90EEE9B9199D6C28AB60668BBC07B2C1D128CF5E24647B03ED20B715F34
Magika powershell
Reporter aachum
Tags:can-vg dropped-by-CountLoader ps1


Avatar
iamaachum
http://45.156.87.62/seo

C2:
can.vg (79.124.40.98:443)

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm base64 encrypted fingerprint obfuscated persistence powershell
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-29T14:27:00Z UTC
Last seen:
2026-04-29T15:01:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Contains functionality to detect sleep reduction / modifications
Early bird code injection technique detected
Encrypted powershell cmdline option found
Found suspicious powershell code related to unpacking or dynamic code loading
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Potential dropper URLs found in powershell memory
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queues an APC in another process (thread injection)
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell Base64 Encoded Invoke Keyword
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Yara detected UnHook AMSI
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1906436 Sample: seo.ps1 Startdate: 29/04/2026 Architecture: WINDOWS Score: 100 42 www.gravatar.com 2->42 44 lb.gravatar.com 2->44 46 3 other IPs or domains 2->46 62 Malicious sample detected (through community Yara rule) 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 Yara detected Powershell download and execute 2->66 68 8 other signatures 2->68 8 powershell.exe 14 75 2->8         started        13 powershell.exe 15 60 2->13         started        15 svchost.exe 2->15         started        signatures3 process4 dnsIp5 48 45.156.87.118, 49691, 49695, 80 SKYLINKNL Germany 8->48 36 C:\Users\user\AppData\...\yo1dwkfj.cmdline, Unicode 8->36 dropped 70 Early bird code injection technique detected 8->70 72 Writes to foreign memory regions 8->72 74 Potential dropper URLs found in powershell memory 8->74 76 Queues an APC in another process (thread injection) 8->76 17 change.exe 8->17         started        21 csc.exe 8->21         started        24 powershell.exe 8->24         started        50 www.gravatar.com 192.0.73.2, 443, 49683 AUTOMATTICUS United States 13->50 52 lb.gravatar.com 192.0.80.240, 443, 49684, 49685 AUTOMATTICUS United States 13->52 38 C:\Users\user\AppData\Local\...\schevnt.xml, XML 13->38 dropped 78 Uses schtasks.exe or at.exe to add and modify task schedules 13->78 80 Found suspicious powershell code related to unpacking or dynamic code loading 13->80 82 Loading BitLocker PowerShell Module 13->82 26 conhost.exe 13->26         started        28 schtasks.exe 1 13->28         started        54 127.0.0.1 unknown unknown 15->54 file6 signatures7 process8 dnsIp9 40 can.vg 79.124.40.98, 443, 49699, 49701 MG2002-ASBG Bulgaria 17->40 56 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 17->56 58 Unusual module load detection (module proxying) 17->58 60 Contains functionality to detect sleep reduction / modifications 17->60 34 Temp_4fd465b606954...b47afae8654ce34.dll, PE32 21->34 dropped 30 cvtres.exe 21->30         started        32 conhost.exe 24->32         started        file10 signatures11 process12
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion execution persistence
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Hide Artifacts: Hidden Window
Obfuscated Files or Information: Command Obfuscation
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC
Author:ditekSHen
Description:Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Rule name:SUSP_PowerShell_Base64_Decode
Author:SECUINFRA Falcon Team
Description:Detects PowerShell code to decode Base64 data. This can yield many FP
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PowerShell (PS) ps1 12d20fc0045eb4aefbeef0498e9c787c7ddcbeea433f99d9430e995a23f63b58

(this sample)

  
Dropped by
CountLoader
  
Delivery method
Distributed via web download

Comments