🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5aee931b8cb6dc4f4037f2fc779bbac62e7eec6f6beffa1cbc3f22a5a75b81be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 20 File information Comments

SHA256 hash: 5aee931b8cb6dc4f4037f2fc779bbac62e7eec6f6beffa1cbc3f22a5a75b81be
SHA3-384 hash: 5c1f52ed07c6da79c75fe321240063767a67279dedf9f16b8355d27f8a6d6bdc997bb47f302266e8361cc95e841c22c9
SHA1 hash: 51221cdc60126c86ee6f1c270221d2e9b1d4c4af
MD5 hash: 70b906ea7940877cc1b425bdef079951
humanhash: muppet-utah-pluto-sink
File name:paylaod_decrypt.ps1
Download: download sample
File size:434'119 bytes
First seen:2026-05-21 04:58:24 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3072:Lit2Emf88xjNn5E048SvwBwrHQIBiWHE/anxb0XRD6ahW7chXTEB5HnsZI2gcif6:62EmE8xOT9EkzAo/chTEB9yQppM6Zy
TLSH T1FE946B386A089469C5F3633FCE939148FE7B5037425E494079AD82903FB9B5ECB71EA4
Magika powershell
Reporter johnk3r
Tags:157-230-222-44 banker decrypted ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
97.4%
Tags:
ransomware shell sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm crypto encrypted fingerprint obfuscated
Verdict:
Malicious
File Type:
csc
First seen:
2026-05-21T02:04:00Z UTC
Last seen:
2026-05-21T02:28:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.PowerShell.Obfus.gen
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.expl.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Creates files in the system32 config directory
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Reads the Security eventlog
Reads the System eventlog
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Suspicious PowerShell Parameter Substring
Suspicious powershell command line found
Uses schtasks.exe or at.exe to add and modify task schedules
Writes a notice file (html or txt) to demand a ransom
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1916889 Sample: paylaod_decrypt.ps1 Startdate: 21/05/2026 Architecture: WINDOWS Score: 100 108 c.windowsk-cdn.com 2->108 110 google.com 2->110 120 Malicious sample detected (through community Yara rule) 2->120 122 Yara detected Powershell download and execute 2->122 124 Yara detected Powershell decode and execute 2->124 126 5 other signatures 2->126 10 MicrosoftEdgeUpdateCore.exe 2->10         started        13 powershell.exe 121 2->13         started        16 svchost.exe 2->16         started        signatures3 process4 file5 128 Suspicious powershell command line found 10->128 130 Reads the Security eventlog 10->130 132 Reads the System eventlog 10->132 18 powershell.exe 10->18         started        104 C:\Users\user\AppData\...\i0plrpwr.cmdline, Unicode 13->104 dropped 106 C:\ProgramData\Microsoft\...\msedgeupdate.txt, ASCII 13->106 dropped 134 Writes a notice file (html or txt) to demand a ransom 13->134 136 Uses schtasks.exe or at.exe to add and modify task schedules 13->136 138 Loading BitLocker PowerShell Module 13->138 21 csc.exe 13->21         started        24 csc.exe 3 13->24         started        26 csc.exe 3 13->26         started        28 11 other processes 13->28 signatures6 process7 file8 114 Suspicious powershell command line found 18->114 116 Creates files in the system32 config directory 18->116 118 Bypasses PowerShell execution policy 18->118 30 powershell.exe 18->30         started        34 csc.exe 18->34         started        37 csc.exe 18->37         started        47 2 other processes 18->47 90 C:\...\MicrosoftEdgeUpdateCore.exe, PE32 21->90 dropped 39 cvtres.exe 21->39         started        92 C:\Users\user\AppData\Local\...\3ljp3yqz.dll, PE32 24->92 dropped 41 cvtres.exe 1 24->41         started        94 C:\Users\user\AppData\Local\...\ignmntfm.dll, PE32 26->94 dropped 43 cvtres.exe 1 26->43         started        96 C:\Users\user\AppData\Local\...\wdnceka2.dll, PE32 28->96 dropped 98 C:\Users\user\AppData\Local\...\i0plrpwr.dll, PE32 28->98 dropped 100 C:\Users\user\AppData\Local\...\bm2couwj.dll, PE32 28->100 dropped 102 2 other files (none is malicious) 28->102 dropped 45 cvtres.exe 1 28->45         started        49 4 other processes 28->49 signatures9 process10 dnsIp11 112 c.windowsk-cdn.com 181.214.221.242, 443, 49698, 49700 BATTLEHOSTBattleHostBR Brazil 30->112 140 Creates files in the system32 config directory 30->140 142 Loading BitLocker PowerShell Module 30->142 51 csc.exe 30->51         started        54 csc.exe 30->54         started        56 csc.exe 30->56         started        64 3 other processes 30->64 74 C:\Windows\Temp\3ejxj01d\3ejxj01d.dll, PE32 34->74 dropped 58 cvtres.exe 34->58         started        76 C:\Windows\Temp\3ox0bbpe\3ox0bbpe.dll, PE32 37->76 dropped 60 cvtres.exe 37->60         started        78 C:\Windows\Temp\z513imf1\z513imf1.dll, PE32 47->78 dropped 62 cvtres.exe 47->62         started        file12 signatures13 process14 file15 80 C:\Windows\Temp\x42gfo1v\x42gfo1v.dll, PE32 51->80 dropped 66 cvtres.exe 51->66         started        82 C:\Windows\Temp\4qxfrera\4qxfrera.dll, PE32 54->82 dropped 68 cvtres.exe 54->68         started        84 C:\Windows\Temp\1pujzjqu\1pujzjqu.dll, PE32 56->84 dropped 70 cvtres.exe 56->70         started        86 C:\Windows\Temp\5faeysyp\5faeysyp.dll, PE32 64->86 dropped 88 C:\Windows\Temp\3hmpz0g3\3hmpz0g3.dll, PE32 64->88 dropped 72 cvtres.exe 64->72         started        process16
Gathering data
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-21 04:59:30 UTC
File Type:
Text (PowerShell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution persistence
Behaviour
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Launches sc.exe
Drops file in System32 directory
Creates new service(s)
Executes dropped EXE
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_decoding
Author:iam-py-test
Description:Detect scripts which are decoding base64 encoded data (mainly Python, may apply to other languages)
Rule name:CMD_Shutdown
Author:adm1n_usa32
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:Detect_Zoom_Invite_malware_RAT_C2
Author:daniyyell
Description:Detects Zoom Invite Call Leading to Malware Hosted in Telegram C2
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC
Author:ditekSHen
Description:Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Rule name:Jupyter_infostealer
Author:CD_R0M_
Description:Rule for Jupyter Infostealer/Solarmarker malware from september 2021-December 2022
Rule name:NET
Author:malware-lu
Rule name:PowerShell_Susp_Parameter_Combo_RID336F
Author:Florian Roth
Description:Detects PowerShell invocation with suspicious parameters
Reference:https://goo.gl/uAic1X
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Suspicious_PS_Strings
Author:Lucas Acha (http://www.lukeacha.com)
Description:observed set of strings which are likely malicious, observed with Jupyter malware.
Reference:http://security5magics.blogspot.com/2020/12/tracking-jupyter-malware.html
Rule name:SUSP_PowerShell_Base64_Decode
Author:SECUINFRA Falcon Team
Description:Detects PowerShell code to decode Base64 data. This can yield many FP
Rule name:SUSP_Scheduled_Tasks_Create_From_Susp_Dir
Author:SECUINFRA Falcon Team
Description:Detects a PowerShell Script that creates a Scheduled Task that runs from an suspicious directory
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:WIN_FileFix_Detection
Author:dogsafetyforeverone
Description:Detects FileFix social engineering technique that launches chained PowerShell and PHP commands from file explorer typed paths
Reference:FileFix social engineering with PowerShell and PHP commands

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments