🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf98f65f2b87eddca5e763e52b55d7fbb0dd2b03688d7501555cf7fb668f5477. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cf98f65f2b87eddca5e763e52b55d7fbb0dd2b03688d7501555cf7fb668f5477
SHA3-384 hash: 2e6409b00aa5189acdb9c9e195aa14cbf0e2acbc9295c72f523f9131256d9de402042eddb1ade1a09fb7e8545743e03a
SHA1 hash: 1069ddda13179fa4ca3909f379a2741124bedf24
MD5 hash: 5f5f868d339aeb58c613fe7eb55e5432
humanhash: india-music-steak-south
File name:cf98f65f2b87eddca5e763e52b55d7fbb0dd2b03688d7501555cf7fb668f5477.ps1
Download: download sample
Signature Kimsuky
File size:391'168 bytes
First seen:2025-12-02 04:59:21 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 6144:qCsBoMhEz5qQsYFninzXOIz4m8SNwO2m5mxzIghV4iTDGSTT431YJF3dO6+tVQb1:qCgIvW4mum57+DE3YWVd0
TLSH T1F3848DB74A57FCBE3ABC2D80D8012E491E1C3947162C9259FEC960BA73E9E54CD2D970
Magika powershell
Reporter KodaDr
Tags:Kimsuky ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
RU RU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 kimsuky nukesped obfuscated obfuscated packed powershell
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Base64 Block Base64 Payload Contains Base64 Block Executable PDB Path PE (Portable Executable) PE File Layout
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-24 03:33:38 UTC
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments