MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1899ff66b76a3f6302fea0afbc26c8452949345d2ea6d987b683c6a0037f22d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1899ff66b76a3f6302fea0afbc26c8452949345d2ea6d987b683c6a0037f22d0
SHA3-384 hash: 94200180efea048f3eccc1825ac531174e945d521df98dd481fd1f7950ada0d4b161de4104bee7cb758c92a17394ff54
SHA1 hash: 07e30496992d7087674cf5542c78856f66ff7737
MD5 hash: 49b3ed4c73d8d5a6613b725d40172590
humanhash: network-two-three-texas
File name:test.ps1
Download: download sample
File size:924'149 bytes
First seen:2020-09-17 20:04:46 UTC
Last seen:2020-09-17 20:05:09 UTC
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 12288:aeeKC+CqCJCqCwCqC7yH5A7+vEeJaZkeq06aQKLI1XqO/bYyoSWjUUFy55576GYj:J
TLSH 891500933651A57705878732395F1AF944BFD709C6CB208AFC8C5A9CB1ECEA3A5987C0
Reporter Dashowl
Tags:NetWalker powershell Ransomware

Intelligence


File Origin
# of uploads :
2
# of downloads :
2'423
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-PowerShell.Ransomware.Netwalker
Status:
Malicious
First seen:
2020-09-14 14:23:47 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments