🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae282788da36b97fde6e1ea9a6492072e90145a81dbc7fa5ce3f90349bb25a3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: ae282788da36b97fde6e1ea9a6492072e90145a81dbc7fa5ce3f90349bb25a3d
SHA3-384 hash: 8131d0dc16544c9ae12163943bef7b86c12fbf5ffa286a2f2ea0ef76e25f90b27f2b7ed85cb9c2e22aef5a8b786ff2fd
SHA1 hash: 35f40aebb4ed7bd59529ceeba202f759d482997c
MD5 hash: 76d1df69cc808b124ddff67e3cecf955
humanhash: alaska-robert-low-bulldog
File name:ae282788da36b97fde6e1ea9a6492072e90145a81dbc7fa5ce3f90349bb25a3d.ps1
Download: download sample
File size:536 bytes
First seen:2026-04-23 09:58:59 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 12:2gDlDzBNKzdN8Q5NmfH0QwhGyCycwhGrPW:2gDl3KhRrmfUHh1CahkPW
TLSH T18EF02BB75841002794CFC1AFEA31A005B261FAEECA063D0EBED9FD3435451B1B162D14
Magika powershell
Reporter JAMESWT_WT
Tags:169-254-169-254 ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated soft-404
Gathering data
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-28 13:20:48 UTC
File Type:
Text (PowerShell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Badlisted process makes network request
Malware Config
Dropper Extraction:
http://169.254.169.254/latest/meta-data/iam/security-credentials/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments