MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ec43a08b98440dbc3e9cb33bf8db2eecc2cd174cb547975a32512d573ad053a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 7 File information Comments

SHA256 hash: 3ec43a08b98440dbc3e9cb33bf8db2eecc2cd174cb547975a32512d573ad053a
SHA3-384 hash: 4e84033efef116b8551155792d3bc471b9d22298b70af250d58beb4942f1eb1cd2f613232710886c866585df6087f912
SHA1 hash: f1fbef4367926e3f6ffabca81e0c133734256175
MD5 hash: b2cbf8450909a3776dc683768dfb26c7
humanhash: jupiter-romeo-summer-nuts
File name:cosmali.ps1
Download: download sample
File size:13'791 bytes
First seen:2025-05-25 12:11:42 UTC
Last seen:2025-12-23 10:32:58 UTC
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 384:6P32JkTEkL6i8KNbkApkykU/ljQhjqK3DIvg2FKhVcKe8BTMeKz4:6fCVXSHlSjqWkiVgARKs
TLSH T1A752243CDAA1FCC043BBB1E0996D3B56209C1B67F7B12B6CF9C518A52924585DB3A18C
Magika powershell
Reporter 01Xyris
Tags:cf-prod-cap--cfd ps1

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
autorun xtreme virus shell
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm base64 crypt evasive fingerprint obfuscated obfuscated persistence powershell powershell
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Drops script or batch files to the startup folder
Encrypted powershell cmdline option found
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Sigma detected: Suspicious PowerShell Parameter Substring
Suspicious powershell command line found
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1698762 Sample: cosmali.ps1 Startdate: 25/05/2025 Architecture: WINDOWS Score: 100 34 cf-cap-load.cfd 2->34 36 ip-api.com 2->36 46 Malicious sample detected (through community Yara rule) 2->46 48 Multi AV Scanner detection for submitted file 2->48 50 Yara detected Powershell download and execute 2->50 52 7 other signatures 2->52 8 powershell.exe 16 43 2->8         started        13 cmd.exe 1 2->13         started        15 powershell.exe 14 41 2->15         started        17 svchost.exe 1 1 2->17         started        signatures3 process4 dnsIp5 42 cf-cap-load.cfd 172.67.204.242, 49713, 49719, 49723 CLOUDFLARENETUS United States 8->42 32 C:\Users\user\AppData\...\UsoUpdate.bat, DOS 8->32 dropped 54 Drops script or batch files to the startup folder 8->54 56 Encrypted powershell cmdline option found 8->56 58 Found suspicious powershell code related to unpacking or dynamic code loading 8->58 19 powershell.exe 17 8->19         started        22 conhost.exe 8->22         started        60 Suspicious powershell command line found 13->60 62 Bypasses PowerShell execution policy 13->62 24 conhost.exe 13->24         started        26 powershell.exe 13->26         started        64 Loading BitLocker PowerShell Module 15->64 28 conhost.exe 15->28         started        44 127.0.0.1 unknown unknown 17->44 file6 signatures7 process8 dnsIp9 38 ip-api.com 208.95.112.1, 49714, 49726, 80 TUT-ASUS United States 19->38 40 193.32.177.63, 49717, 49727, 49728 AS40676US Russian Federation 19->40 30 conhost.exe 19->30         started        process10
Threat name:
Script-PowerShell.Downloader.Boxter
Status:
Malicious
First seen:
2025-05-11 01:39:00 UTC
File Type:
Text (Batch)
AV detection:
8 of 38 (21.05%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Looks up external IP address via web service
Drops startup file
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://cf-cap-load.cfd/static/startup.bat
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Detect_Zoom_Invite_malware_RAT_C2
Author:daniyyell
Description:Detects Zoom Invite Call Leading to Malware Hosted in Telegram C2
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:SUSP_PowerShell_Base64_Decode
Author:SECUINFRA Falcon Team
Description:Detects PowerShell code to decode Base64 data. This can yield many FP
Rule name:SUSP_PS1_FromBase64String_Content_Indicator_RID3714
Author:Florian Roth
Description:Detects suspicious base64 encoded PowerShell expressions
Reference:https://gist.github.com/Neo23x0/6af876ee72b51676c82a2db8d2cd3639
Rule name:SUSP_Scheduled_Tasks_Create_From_Susp_Dir
Author:SECUINFRA Falcon Team
Description:Detects a PowerShell Script that creates a Scheduled Task that runs from an suspicious directory

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropped by
XWorm

Comments