MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb67fa07897b73aca77311e4d23bbbbe496e8570338f36305704e487034fd0ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: bb67fa07897b73aca77311e4d23bbbbe496e8570338f36305704e487034fd0ad
SHA3-384 hash: 8664e85e798e908693dd643ec27de7b18c09239869aa16337957ae6b957cf721ae75dd210bfe52873e78fda6a558ff26
SHA1 hash: aa9535646b0cc8ea29fd85bd78fca8721651b299
MD5 hash: af90352dcdeb09d4a19ed975923ed038
humanhash: aspen-sodium-item-alabama
File name:ps_z.ps1
Download: download sample
File size:774 bytes
First seen:2025-03-21 19:08:08 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 12:o6wrVvKQKMf6+j+d5MOdQ6w6qRRdXh5A1ifw4A2fB7GTf:DwrVHf6+j+d552CqbdRBfwKp7Y
TLSH T10201D50C6683C7355483B40ED585C03DD63B7A6127786A1089E59702CE53D48D7FEFA7
Magika powershell
Reporter JAMESWT_WT
Tags:8-218-50-207 ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
virus sage blic
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl
Score:
56 / 100
Signature
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Dot net compiler compiles file from suspicious location
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1645479 Sample: ps_z.ps1 Startdate: 21/03/2025 Architecture: WINDOWS Score: 56 21 Multi AV Scanner detection for submitted file 2->21 23 Joe Sandbox ML detected suspicious sample 2->23 25 Sigma detected: Dot net compiler compiles file from suspicious location 2->25 7 powershell.exe 26 2->7         started        process3 file4 17 C:\Users\user\AppData\...\kyfp0njo.cmdline, Unicode 7->17 dropped 10 csc.exe 3 7->10         started        13 conhost.exe 7->13         started        process5 file6 19 C:\Users\user\AppData\Local\...\kyfp0njo.dll, PE32 10->19 dropped 15 cvtres.exe 1 10->15         started        process7
Threat name:
Script-PowerShell.Trojan.Boxter
Status:
Malicious
First seen:
2025-03-21 13:20:02 UTC
File Type:
Text (CSharp)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PowerShell (PS) ps1 bb67fa07897b73aca77311e4d23bbbbe496e8570338f36305704e487034fd0ad

(this sample)

  
Delivery method
Distributed via web download

Comments