🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc15ab39b2171cb22e4afd55d92c2994707b9cebf4edf44b150dbbbbe209df2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: dc15ab39b2171cb22e4afd55d92c2994707b9cebf4edf44b150dbbbbe209df2d
SHA3-384 hash: b6fbd28d5c9a9752307dd4c6c0954b98619d4f8229065be465e78ec157a8f4d83d9091550b02d8a574185eaa4f5fd872
SHA1 hash: 4682c97c7e51158320a40a98415341ba8cf117d7
MD5 hash: 0a9c22079c898fc112e67ce1caff8f54
humanhash: friend-mars-ten-alabama
File name:Kimsuky TA427.ps1
Download: download sample
Signature Kimsuky
File size:2'871 bytes
First seen:2025-06-11 07:04:44 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:BRiw7ZcrEjP1dBwJDmCnPodG0rhgqO4gOWlp0t2bpW6CmeINVh/MXtmv:BU41dBcmCnmt2N/BeINT+8
TLSH T1F1510D1583A09AE083EF35B2BAC15C1AFE745ED04259E028F4A7F116C424FFC1E589B7
Magika javascript
Reporter JAMESWT_WT
Tags:Kimsuky ps1 TA427

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
AI detected malicious Powershell script
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1711945 Sample: Kimsuky TA427.ps1 Startdate: 11/06/2025 Architecture: WINDOWS Score: 23 10 AI detected malicious Powershell script 2->10 6 powershell.exe 11 2->6         started        process3 process4 8 conhost.exe 6->8         started       
Threat name:
Script-JS.Trojan.ObfuscatedJS
Status:
Malicious
First seen:
2025-06-10 03:26:10 UTC
File Type:
Text
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments