🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54e59a0b9ee97b47e69f64afd495dbc192fa212703f03b7f8396d5b2247fb089. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 54e59a0b9ee97b47e69f64afd495dbc192fa212703f03b7f8396d5b2247fb089
SHA3-384 hash: 58ffb84be33034167c13cb990a1677eba1fb74d83228b3f77c2a6ccc16802bdd0430328a2f8e0afd1362d3653f23caab
SHA1 hash: b717cdd66c5e7c99788ea9fae56100719c653bc4
MD5 hash: f113221694a306d49b88da10c7633555
humanhash: johnny-utah-tango-bacon
File name:bypass.ps1
Download: download sample
File size:2'182 bytes
First seen:2026-04-09 09:20:42 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:UYn1oDH+Wm5IFEtfgVadiTDkrFcSRWE4TYLtt2yRwF1RrA:UYn1oDKcaihEiirSfRs
TLSH T14941F20C57956A7F48E77418E995CCDEE55300B122BB18117DFD93325FA7104E23A73A
Magika powershell
Reporter Joker
Tags:amsi ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.9%
Tags:
virus shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
exploit powershell
Verdict:
Clean
File Type:
unix shell
First seen:
2026-01-16T19:57:00Z UTC
Last seen:
2026-04-10T13:21:00Z UTC
Hits:
~10
Detections:
PDM:Trojan.Win32.Generic PDM:Exploit.Win32.Generic Exploit.Win32.ChecksumController.b
Gathering data
Verdict:
Malicious
Threat:
Exploit.Win32.ChecksumController
Threat name:
Text.Trojan.Disable
Status:
Malicious
First seen:
2026-01-17 02:11:37 UTC
File Type:
Text (PowerShell)
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments