🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa4ceb7641d5f44fbb1f4b2dd6a4952059cdd909d14b2d21dc1f0b49af0b16c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: aa4ceb7641d5f44fbb1f4b2dd6a4952059cdd909d14b2d21dc1f0b49af0b16c7
SHA3-384 hash: 6db97afde44cc33d6b4707d4f91d5f0550adf6009012b23a05afde11ff49ce1ecb60795e5158e6c1854d685a436512db
SHA1 hash: f7ad2fbb0ec4012597e95a1e89b814417ae521e0
MD5 hash: 8a674a3c2c8a60026431e2398273b069
humanhash: glucose-angel-spring-white
File name:aa4ceb7641d5f44fbb1f4b2dd6a4952059cdd909d14b2d21dc1f0b49af0b16c7.ps1
Download: download sample
File size:2'163 bytes
First seen:2026-05-12 10:24:55 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:fxJ8X6zmjrbMym07DPjRWmU+hSHH0PLTo0V+uMVQz:0B/LiYq0fo0bMVo
TLSH T1474184D97EC85C84F3BF422DD77B9ABFA5131A99D89ACE1C011C82C23E21AD17E45852
Magika powershell
Reporter JAMESWT_WT
Tags:jicinvestments-monster ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
xtreme shell sage
Verdict:
Malicious
File Type:
text
First seen:
2026-05-12T07:39:00Z UTC
Last seen:
2026-05-12T08:10:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Agent.sb PDM:Trojan.Win32.Generic
Gathering data
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-04-26 06:06:15 UTC
File Type:
Text (Batch)
AV detection:
6 of 24 (25.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments