🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5898cab97f4e82f4b3fc1ded1f26c7c3451ab137dcffffeaa68e6360558ad607. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 7 File information Comments

SHA256 hash: 5898cab97f4e82f4b3fc1ded1f26c7c3451ab137dcffffeaa68e6360558ad607
SHA3-384 hash: 7d2212307793b9e5dcc4c11361e51f8e63b298e91d8e862af75f52974f3932e9c914ed9c23cc3df482a69f01018b7f1c
SHA1 hash: cbb15747a58326f57a693d3b6d9dccbd619c70fb
MD5 hash: 41b3f3fc28d638d136c030290d30c29b
humanhash: white-mango-violet-charlie
File name:update.ps1
Download: download sample
File size:11'992 bytes
First seen:2026-10-10 20:56:27 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 192:XNu4AkGDkQ4pj2qnukql7mZiIKFIx/3P+5KIQcCDP3CLiVj5I6gCYh5KIQcee:XMXKQlx6+5KIQzLMc8h5KIQE
TLSH T13532B85ABF032058C6F3DBBFBCD35209EA524037898B3818B5EDD1952FB196847AD14C
Magika powershell
Reporter smica83
Tags:ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug crypto dropper evasive evasive expand fingerprint lolbin masquerade obfuscated obfuscated reconnaissance
Result
Threat name:
Salat Stealer, Xmrig
Detection:
malicious
Classification:
troj.spyw.expl.evad.mine
Score:
100 / 100
Signature
Adds extensions / path to Windows Defender exclusion list (Registry)
AI detected malicious Powershell script
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Connects to a pastebin service (likely for C&C)
Creates multiple autostart registry keys
Drops password protected ZIP file
Drops VBS files to the startup folder
Found API chain indicative of debugger detection
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
PE file has nameless sections
Powershell connects to network
Powershell drops PE file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample is not signed and drops a device driver
Sigma detected: Drops script at startup location
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Sigma detected: Windows Binaries Write Suspicious Extensions
Suricata IDS alerts for network traffic
Suspicious access to claude desktop data directory by non-Claude process
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Powershell download and execute
Yara detected Salat Stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1985362 Sample: update.ps1 Startdate: 10/10/2026 Architecture: WINDOWS Score: 100 130 pastebin.com 2->130 132 rabbids.su 2->132 134 9 other IPs or domains 2->134 162 Suricata IDS alerts for network traffic 2->162 164 Malicious sample detected (through community Yara rule) 2->164 166 Antivirus detection for URL or domain 2->166 170 12 other signatures 2->170 11 powershell.exe 14 35 2->11         started        16 MicrosoftCacheAssistant.exe 2->16         started        18 MicrosoftUpdateAssistant.exe 2->18         started        20 12 other processes 2->20 signatures3 168 Connects to a pastebin service (likely for C&C) 130->168 process4 dnsIp5 148 rabbids.cc 196.251.107.72, 443, 49702, 49709 FEMOITGB Germany 11->148 150 ipwho.is 104.20.44.133, 443, 49699 CLOUDFLARENET-CloudflareIncUS Canada 11->150 108 C:\Users\user\AppData\Local\...\Rabbids.exe, PE32+ 11->108 dropped 110 C:\Users\user\AppData\Local\Temp\...\7za.exe, PE32 11->110 dropped 200 Found many strings related to Crypto-Wallets (likely being stolen) 11->200 202 Powershell connects to network 11->202 204 Powershell drops PE file 11->204 22 Rabbids.exe 11->22         started        26 javaw.exe 11->26         started        29 7za.exe 7 11->29         started        33 2 other processes 11->33 206 Multi AV Scanner detection for dropped file 16->206 152 127.0.0.1 unknown unknown 20->152 31 MpCmdRun.exe 20->31         started        file6 signatures7 process8 dnsIp9 96 C:\Users\user\AppData\Local\...\Rabbids.exe, PE32+ 22->96 dropped 174 Multi AV Scanner detection for dropped file 22->174 176 Adds extensions / path to Windows Defender exclusion list (Registry) 22->176 35 Rabbids.exe 22->35         started        146 mog-battle-with-rabbids.cc 104.21.92.68, 443, 49716 CLOUDFLARENET-CloudflareIncUS Canada 26->146 178 Found many strings related to Crypto-Wallets (likely being stolen) 26->178 180 Found API chain indicative of debugger detection 26->180 182 Tries to harvest and steal ftp login credentials 26->182 184 9 other signatures 26->184 39 chrome.exe 26->39         started        98 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 29->98 dropped 100 C:\Users\user\AppData\Local\Temp\...\jli.dll, PE32+ 29->100 dropped 102 C:\Users\user\AppData\Local\...\javaw.exe, PE32+ 29->102 dropped 42 conhost.exe 31->42         started        file10 signatures11 process12 dnsIp13 92 C:\Users\user\AppData\...\RuntimeSync.exe, PE32+ 35->92 dropped 94 C:\Users\user\AppData\...\RuntimeBroker.exe, PE32+ 35->94 dropped 172 Multi AV Scanner detection for dropped file 35->172 44 RuntimeBroker.exe 35->44         started        49 RuntimeSync.exe 35->49         started        136 192.168.2.4, 137, 138, 443 unknown unknown 39->136 51 chrome.exe 39->51         started        53 chrome.exe 39->53         started        file14 signatures15 process16 dnsIp17 154 pastebin.com 104.20.29.150, 443, 49745, 49747 CLOUDFLARENET-CloudflareIncUS Canada 44->154 112 C:\Users\user\AppData\...\taskmgr_hook.dll, PE32+ 44->112 dropped 114 C:\Users\user\AppData\Local\...\gg.exe, PE32 44->114 dropped 116 C:\Users\user\...\MicrosoftUpdateWorker.exe, PE32+ 44->116 dropped 126 5 other malicious files 44->126 dropped 208 Multi AV Scanner detection for dropped file 44->208 210 Found strings related to Crypto-Mining 44->210 212 Drops VBS files to the startup folder 44->212 222 3 other signatures 44->222 55 gg.exe 44->55         started        60 MicrosoftUpdateWorker.exe 44->60         started        62 MicrosoftUpdateHealth.exe 44->62         started        70 5 other processes 44->70 118 C:\Users\user\AppData\...\taskmgr_hook.dll, PE32+ 49->118 dropped 120 C:\Users\user\AppData\...\WinRing0x64.sys, PE32+ 49->120 dropped 122 C:\Users\user\...\MicrosoftCacheWorker.exe, PE32+ 49->122 dropped 128 5 other malicious files 49->128 dropped 214 Creates multiple autostart registry keys 49->214 216 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 49->216 218 Adds extensions / path to Windows Defender exclusion list (Registry) 49->218 220 Sample is not signed and drops a device driver 49->220 64 MicrosoftCacheWorker.exe 49->64         started        66 MicrosoftCacheHealth.exe 49->66         started        68 schtasks.exe 49->68         started        72 4 other processes 49->72 156 play.google.com 142.250.31.113, 443, 49730 GOOGLE-GoogleLLCUS United States 51->156 158 www.google.com 142.251.156.119, 443, 49717, 49722 GOOGLE-GoogleLLCUS United States 51->158 160 3 other IPs or domains 51->160 124 Chrome Cache Entry: 303, PDP-11 51->124 dropped file18 signatures19 process20 dnsIp21 138 dns.google 8.8.8.8, 443, 49750 GOOGLE-GoogleLLCUS United States 55->138 140 cloudflare-dns.com 104.16.249.249, 443, 49749 CLOUDFLARENET-CloudflareIncUS Canada 55->140 142 sa1atik.cn 64.204.180.24, 443, 49752 AS-BLAZINGSEO-BlazingSEOLLCUS Germany 55->142 104 C:\...\qrNwbQxjmpt8iD8V.exe, PE32 55->104 dropped 106 C:\Program Files (x86)\...\OUQLxvldRpr3.exe, PE32 55->106 dropped 186 Multi AV Scanner detection for dropped file 55->186 188 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 55->188 190 Creates multiple autostart registry keys 55->190 74 OUQLxvldRpr3.exe 55->74         started        144 pool.hashvault.pro 208.167.233.7, 443, 49746 AS-VULTR-TheConstantCompanyLLCUS United States 60->144 192 Antivirus detection for dropped file 60->192 76 conhost.exe 60->76         started        194 Hides threads from debuggers 64->194 196 Unusual module load detection (module proxying) 64->196 198 Found direct / indirect Syscall (likely to bypass EDR) 64->198 86 2 other processes 64->86 78 conhost.exe 68->78         started        80 conhost.exe 70->80         started        82 conhost.exe 70->82         started        88 3 other processes 70->88 84 conhost.exe 72->84         started        90 3 other processes 72->90 file22 signatures23 process24
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
PowerShell T1059.001 T1105
Result
Malware family:
Score:
  10/10
Tags:
family:salatstealer family:xmrig defense_evasion discovery execution miner persistence spyware stealer trojan upx
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
UPX packed file
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Contacts third-party web service commonly abused for C2
Executes a file named after a Windows system binary
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Windows security modification
Badlisted process makes network request
Downloads MZ/PE file
Modifies Windows Firewall
Detect SalatStealer payload
Family: salatstealer
Family: xmrig
Windows security bypass
XMRig Miner payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SCRIPT_Dropper_Unknown_ForgeAuto_628f41a1
Author:Marjoriefort
Description:Detects Unknown (script_js, etat binaire)
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments