MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 948c59b8b18573bc1b28659e240ef09d1356a0a5cc01db5b458bde9dd2cafd8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 948c59b8b18573bc1b28659e240ef09d1356a0a5cc01db5b458bde9dd2cafd8b
SHA3-384 hash: d3b27c3d3efbbf90409d59e68242e2cd57e15ff5d8a22c3e3af7644ed3302aab56495d25d85724549f6f29685a89caf7
SHA1 hash: 2af92976d31f90e662149054eb825d8661c5630e
MD5 hash: ea9b67e488be600cc8fe1c749a9a8ee3
humanhash: alanine-mobile-august-twenty
File name:948c59b8b18573bc1b28659e240ef09d1356a0a5cc01db5b458bde9dd2cafd8b.ps1
Download: download sample
File size:8'947 bytes
First seen:2026-07-23 13:12:41 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 192:1FIVYCTYAOam0uiEynhiiIFVpFhwK+yi3inh/iIFLpFhwK+yiQui/km4Z0J/K0JG:1q6zv1yicZ50FIGC4edm9A
TLSH T1BB02875BF997446597D3227B9DC80188F52B444F420E1F62BA9C83C16F704BCCFEA68A
Magika powershell
Reporter JAMESWT_WT
Tags:completstep-com ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Verdict:
Suspicious
Labled as:
PowerShell/TrojanDownloader.Agent
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Malware Config
Dropper Extraction:
http://135.181.127.216/dl-callback/94rwryy7-6vyvayjx-hw6uuu6v-6dgkme2r/Safe-1.zip/a93e72898c9a243079d829165c38a013
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments