MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59378e29d34ff5bd1a2f9f14cb71b0a443ca9fb9e7a6162305c3b94ec65f907e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 59378e29d34ff5bd1a2f9f14cb71b0a443ca9fb9e7a6162305c3b94ec65f907e
SHA3-384 hash: 2d7267903568518d3aef014c1796a46845321c4df86853d7aee531e811f6cd72880a3657c44d76e01ca30aa4ac4c38ee
SHA1 hash: e47a5348c14cc678fa41a1d6d770e0d33dbe5aec
MD5 hash: 27f908d73bbda3de34420c391dc1c643
humanhash: butter-bacon-tennessee-fish
File name:Rj6hPQQOhiLf9Qci.ps1
Download: download sample
File size:4'622 bytes
First seen:2026-07-23 13:13:54 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 96:3jgPVVepFtVHptKqrlonffdfs9httmrQV6V8BoORVGGmop49FtS66jSpNPVF:sPVUpFvJtJqnf1KttmEq8BTaG4rtS66g
TLSH T13B915B496723A4D7A3DE7ABF96D49BB0A728703001F73C8582BA00B1A5D6151CD301FA
Magika powershell
Reporter JAMESWT_WT
Tags:completstep-com ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 dropper obfuscated powershell
Verdict:
Malicious
Labled as:
PowerShell/TrojanDropper.Agent
Verdict:
Malicious
File Type:
ps1
First seen:
2026-07-23T11:16:00Z UTC
Last seen:
2026-07-24T05:24:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-PowerShell.Trojan.Boxter
Status:
Malicious
First seen:
2026-07-23 13:10:10 UTC
File Type:
Text (PowerShell)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
http://135.181.127.216/dl-callback/94rwryy7-6vyvayjx-hw6uuu6v-6dgkme2r/Safe-1.zip/cbca0ddfdc6dde04afd79f74f2ad52e4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments