MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63a3edf63016ee186c11eb7662ae46d3e5c8e11db99c05c4721ca7ab0e2f4684. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 63a3edf63016ee186c11eb7662ae46d3e5c8e11db99c05c4721ca7ab0e2f4684
SHA3-384 hash: ab76b740dbeca18381c92bf89f5d2332e2119c5eea8afbd1133c3b903fd98f28e0666ec4bf265d074b28ebe12ac798ea
SHA1 hash: f62a3976f2683ae5689105f0f6fd99f7464be28a
MD5 hash: 56f6757d867758e6f7a739598c00e2ad
humanhash: asparagus-river-double-maine
File name:start.txt
Download: download sample
File size:3'176 bytes
First seen:2020-12-12 15:35:30 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 96:2DYOFcr4MeQHlnrj+6gywLUMpUFv/3WQtrRb8Rgwg:LO2M5QHlnr/gyw9pwv7rKM
TLSH F7616C97310458E0ED917F53CB4F0B004B061AC9A58682F0DB19A63513B5B9EAE9EF3B
Reporter vm001cn
Tags:Loader ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
233
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Script-PowerShell.Packed.Generic
Status:
Suspicious
First seen:
2020-09-09 05:16:33 UTC
AV detection:
17 of 27 (62.96%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments