🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a043a0f20a4bf6ca46ee564f21dc535636060c32efe057ed7df7712da2177acf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: a043a0f20a4bf6ca46ee564f21dc535636060c32efe057ed7df7712da2177acf
SHA3-384 hash: 36e908b53f80be7c64b4c30315c2a209e35ecd6afe2954ab3b6a895cfa6e94fbc1fa9c67c87ef02c669de2aa104d4771
SHA1 hash: 7429f065e94f008a20abe646421fdd4b92942e15
MD5 hash: 28719fa8d6295c21c7958ca1bbae2462
humanhash: social-floor-robin-summer
File name:sample.ps1
Download: download sample
File size:2'179 bytes
First seen:2026-06-01 19:29:46 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:MpW0EZ0qois9XSaGDdAgARNECqQtXRa1ZqBc8SpHgtE/PGNOIuW:t9Z3shSHdA3NEhEa6c8bt6PXIX
TLSH T1E34165B1E818A4C4C27AE5279667FEA9BA362097DC4E14E901ED13290E033D8ADD3C81
Magika powershell
Reporter Anonymous
Tags:ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
134
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
xtreme shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
dropper encrypted evasive obfuscated powershell
Verdict:
Malicious
File Type:
ps1
First seen:
2026-06-01T16:53:00Z UTC
Last seen:
2026-06-03T02:52:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Agent.sb
Gathering data
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-01 19:22:47 UTC
File Type:
Text (PowerShell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments