🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a77607114569b8d4e9b337fac2c0d56b97db80495c9d9f8746061f41a56fdc0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 7 File information Comments

SHA256 hash: a77607114569b8d4e9b337fac2c0d56b97db80495c9d9f8746061f41a56fdc0f
SHA3-384 hash: f41d3a1e385ddd3832a88a48c971b31850315af5fc54e6839cba058bfbf37f3697d981af35429c704a102c54ef87e491
SHA1 hash: 58a73803db5189804d381fdb5fb402538edbc72e
MD5 hash: 0f61287fd388bd9da97d8910bf8f4989
humanhash: may-comet-helium-april
File name:a77607114569b8d4e9b337fac2c0d56b97db80495c9d9f8746061f41a56fdc0f.ps1
Download: download sample
File size:23'109 bytes
First seen:2026-05-21 07:11:13 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 384:GOXigxbASlARyFeGpD4tn3Txa9NDC5ziafz6aEIc6NQ9YJ7QSMGe6yrZH:o6cSlpD4tn3TxMDUzfDcsjkSBzy9H
TLSH T131A2E896DD8B2D5D9BB022B620CE58E54B6E03CF106508ED271ED3C8AEFD009D9E25DD
Magika powershell
Reporter JAMESWT_WT
Tags:89-124-94-238 ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
autorun shell agent sage
Verdict:
Malicious
File Type:
ps1
First seen:
2026-04-07T09:36:00Z UTC
Last seen:
2026-05-21T18:53:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-04-07 04:11:57 UTC
File Type:
Text (PowerShell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
http://89.124.94.238:8888
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:PowerShell_Susp_Parameter_Combo_RID336F
Author:Florian Roth
Description:Detects PowerShell invocation with suspicious parameters
Reference:https://goo.gl/uAic1X
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments