MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 9
| SHA256 hash: | 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda |
|---|---|
| SHA3-384 hash: | cb700c1a6d9a00208217822bd45a7046a339aa45fd361b78801e9a0d24019c0639faee44f7dc6db6c8ae049fc48d7b87 |
| SHA1 hash: | aafefa11530573c8eda0a78d4c626bcb41dc21c9 |
| MD5 hash: | 845772e1d111a09afdd50816d0babe2f |
| humanhash: | oranges-oklahoma-zulu-delaware |
| File name: | ps1005.ps1 |
| Download: | download sample |
| File size: | 230 bytes |
| First seen: | 2024-11-19 11:15:35 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 3:EMV0CGkGPnM2SqM5BLu3qvGNAZ1DWRLnm+EAtsccejuw3CMpmP9MBGXeMEeAhFIH:lVh0I35BLu3q183CVMBOe5fEgZatuxsn |
| TLSH | T1DAD0976EF21E41E0010CA27B0C53A37420C12A2148F62254BB1CE908F2F16662908471 |
| Magika | powershell |
| Reporter | |
| Tags: | ps1 |
Intelligence
File Origin
# of uploads :
1
# of downloads :
84
Origin country :
GRVendor Threat Intelligence
Verdict:
Malicious
Score:
70.0%
Tags:
shell
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Trojan.Agent
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Score:
86%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Script-PowerShell.Trojan.ViperSoftX
Status:
Malicious
First seen:
2024-11-15 21:46:49 UTC
File Type:
Text
AV detection:
19 of 38 (50.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
ps1 413c0a3d17c8e9dada75d331b0a2b448b1eafacf06f5187a2c35aebec65b7fda
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.