MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 90b24cd5340f1380fcd47b5231c2fc94922faf52182cd912b02b524d1f7a9fe4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 90b24cd5340f1380fcd47b5231c2fc94922faf52182cd912b02b524d1f7a9fe4
SHA3-384 hash: 8bdf1a374602c21d144d0fe474059bad8e8e50a840bdbf1701080db6cb66feea56139c45199be76cb615acc48b1d5e84
SHA1 hash: 6dad04bc3f3280d018e3b30022af8d7aa02f8d78
MD5 hash: 356ebab3b67a5dc8e1eb04d3b33b6b94
humanhash: beer-nevada-salami-nevada
File name:token_steal.ps1
Download: download sample
File size:2'979 bytes
First seen:2026-06-11 19:53:39 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:D5jMCC6ntGg5J1K6+WtIRWWcMDF/okgygmXwQovsoINCo8NBCt5c+Ocq3BlgvNAB:D5jMS/gW1Yx5XPGDhN3ztNl800cWmP
TLSH T16651646823071134085A651939CA858BE613899707BFAC327AED43F1DF0522AD1FBF7B
Magika cs
Reporter skocherhan
Tags:161-248-87-10 opendir ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments