🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52cc4b42c9ada8a8fa51f8b38a0d1dc83cd8b07fba79d43c3a568d7f38496a41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 52cc4b42c9ada8a8fa51f8b38a0d1dc83cd8b07fba79d43c3a568d7f38496a41
SHA3-384 hash: da94a4729b1a7d89ca1e3647c630416c6aee89e8ebe3abc24d13d40981c3aa0bf79599c6d7c9b68744e17dacbf022e0d
SHA1 hash: cbaee39c1cd15af4993e6a46668aa0905090be89
MD5 hash: 99f9419d756729bc97d687f845d77783
humanhash: whiskey-potato-ack-shade
File name:G3892.ps1
Download: download sample
File size:7'890 bytes
First seen:2025-02-05 09:13:58 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 192:cB+qej929s0Iclef57+rCOteDj7Po3zGjPh:cwTthtB0CO+f
TLSH T13EF1D60EA8F2FDD60C00A4DC5EB50C2B76F869DFC0375B96A8EFC34B2858D4056D592A
Magika powershell
Reporter JAMESWT_WT
Tags:74-50-94-175 DropBox ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
150
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
malware
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
25 / 100
Signature
Joe Sandbox ML detected suspicious sample
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1607276 Sample: G3892.ps1 Startdate: 05/02/2025 Architecture: WINDOWS Score: 25 11 18.31.95.13.in-addr.arpa 2->11 13 Joe Sandbox ML detected suspicious sample 2->13 7 powershell.exe 14 21 2->7         started        signatures3 process4 process5 9 conhost.exe 7->9         started       
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments