MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda
SHA3-384 hash: cb700c1a6d9a00208217822bd45a7046a339aa45fd361b78801e9a0d24019c0639faee44f7dc6db6c8ae049fc48d7b87
SHA1 hash: aafefa11530573c8eda0a78d4c626bcb41dc21c9
MD5 hash: 845772e1d111a09afdd50816d0babe2f
humanhash: oranges-oklahoma-zulu-delaware
File name:ps1005.ps1
Download: download sample
File size:230 bytes
First seen:2024-11-19 11:15:35 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:EMV0CGkGPnM2SqM5BLu3qvGNAZ1DWRLnm+EAtsccejuw3CMpmP9MBGXeMEeAhFIH:lVh0I35BLu3q183CVMBOe5fEgZatuxsn
TLSH T1DAD0976EF21E41E0010CA27B0C53A37420C12A2148F62254BB1CE908F2F16662908471
Magika powershell
Reporter Joker
Tags:ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
GR GR
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70.0%
Tags:
shell
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Script-PowerShell.Trojan.ViperSoftX
Status:
Malicious
First seen:
2024-11-15 21:46:49 UTC
File Type:
Text
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PowerShell (PS) ps1 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda

(this sample)

  
Delivery method
Distributed via web download

Comments