🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b65185390624b4222b0ef816bc01b735096429ca8da8e2a040c5a61e6b44752. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3b65185390624b4222b0ef816bc01b735096429ca8da8e2a040c5a61e6b44752
SHA3-384 hash: e3f01c6b5a7079ff544cf7c2d4b638fce58e263c10dfc53f1005f073bf339f6569d687ac122db3067fb828069ffffc10
SHA1 hash: 8b66b23468ebc384b993969ae44317e687a5b2a9
MD5 hash: 7b25c90ffe2c2bfb7d6d52ab44b3191c
humanhash: video-enemy-solar-lactose
File name:hongyang2015.com.ps1
Download: download sample
File size:20'092 bytes
First seen:2026-07-19 07:13:28 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/html
ssdeep 384:X4FTAsXe7FUFh/+4MA6ksb7RYsa7bWkkg1k4iPiliri/iIk4i7aiyKi8iJiyILnL:Xe8sXe7FUFk3usafWkkg1kVKUO6IkV7J
TLSH T12D92B71669B300226913C0BC6BE79746333180079645CE6A3FAC5294DF8AEE5ADF37DC
Magika html
Reporter JAMESWT_WT
Tags:85-239-149-178 booking deyetechnical-com hongyang2015-com ps1 Spam-ITA v0hkpadr04mbz5lkearqa-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
91.7%
Tags:
malware
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aidetect masquerade phishing
Verdict:
Malicious
File Type:
html
First seen:
2026-05-10T11:28:00Z UTC
Last seen:
2026-07-21T01:23:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Html SVG
Threat name:
Document-HTML.Trojan.FakeCaptcha
Status:
Malicious
First seen:
2026-05-12 17:15:10 UTC
File Type:
Text (HTML)
Extracted files:
4
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments