🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bead2dfd37e98f60c258f78f443c7cbcec441f012c503ae62eb3746012a3415. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: 4bead2dfd37e98f60c258f78f443c7cbcec441f012c503ae62eb3746012a3415
SHA3-384 hash: eae3975f0013631079236eefc577fd52d413d21c5bfe89249609aa748c950e6209009d6348cccf7c670398f7dc79af81
SHA1 hash: 58743a515ec3f411ae4fbe359030d57dbdf8286a
MD5 hash: 51a185cf0325103fb7ef7e23cce0f33e
humanhash: kansas-ink-september-west
File name:seo-finalize.ps1
Download: download sample
File size:781'616 bytes
First seen:2026-04-29 17:16:36 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 1536:x194Z2MlQ/4dni1n5kLpFPl9CcxHBh8m3NOf57aNWhAYEntetwlLbQBL1rs0IL8L:x7kkl
TLSH T161F470E317EC46EE6B9448DA814D3A0754FBC67B2C5E424DF4E21943F13E921BA26B70
Magika powershell
Reporter aachum
Tags:can-vg dropped-by-CountLoader ps1


Avatar
iamaachum
http://45.156.87.118/seo-finalize

C2:
can.vg (79.124.40.98:443)

Intelligence


File Origin
# of uploads :
1
# of downloads :
130
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm base64 encrypted fingerprint obfuscated powershell
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-29T00:55:00Z UTC
Last seen:
2026-05-01T00:53:00Z UTC
Hits:
~10
Detections:
Trojan-Dropper.PowerShell.Agent.afw
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
Compiles code for process injection (via .Net compiler)
Early bird code injection technique detected
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sigma detected: Dot net compiler compiles file from suspicious location
Writes to foreign memory regions
Yara detected Powershell decode and execute
Yara detected UnHook AMSI
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1906434 Sample: seo-finalize.ps1 Startdate: 29/04/2026 Architecture: WINDOWS Score: 100 32 Malicious sample detected (through community Yara rule) 2->32 34 Multi AV Scanner detection for submitted file 2->34 36 Yara detected Powershell decode and execute 2->36 38 3 other signatures 2->38 7 powershell.exe 72 2->7         started        process3 file4 26 C:\Users\user\AppData\...\ydcsfytv.cmdline, Unicode 7->26 dropped 28 C:\Users\user\AppData\Local\...\ydcsfytv.0.cs, Unicode 7->28 dropped 40 Early bird code injection technique detected 7->40 42 Writes to foreign memory regions 7->42 44 Found suspicious powershell code related to unpacking or dynamic code loading 7->44 46 3 other signatures 7->46 11 csc.exe 4 7->11         started        14 powershell.exe 13 7->14         started        16 choice.exe 1 7->16         started        18 conhost.exe 7->18         started        signatures5 process6 file7 30 Temp_52420d5888294...1cbf0726df85f9e.dll, PE32 11->30 dropped 20 cvtres.exe 1 11->20         started        22 conhost.exe 14->22         started        24 WerFault.exe 20 16 16->24         started        process8
Gathering data
Verdict:
Malicious
Threat:
Trojan-Dropper.PowerShell.Agent
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-29 17:17:02 UTC
File Type:
Text (PowerShell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC
Author:ditekSHen
Description:Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PowerShell (PS) ps1 4bead2dfd37e98f60c258f78f443c7cbcec441f012c503ae62eb3746012a3415

(this sample)

  
Delivery method
Distributed via web download

Comments