🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5eba0c505759a2ddd4a03332caf54ee531a062dacf19c12c015221ab3065aad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e5eba0c505759a2ddd4a03332caf54ee531a062dacf19c12c015221ab3065aad
SHA3-384 hash: 5b2afdd74ecf3bfc8ababf10590c6436c2649810480a225aaa71d0762556b1635ac13146dc8c02535e1d2f63ed3471cb
SHA1 hash: 2d71e447c5ad42084a52f5e7e07bef0b0850a339
MD5 hash: 4287f1ced950519bfdd76177d0139726
humanhash: paris-north-pluto-pip
File name:b
Download: download sample
Signature KongTuke
File size:1'196 bytes
First seen:2026-09-11 17:37:46 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 24:QDjVuV0cVRYifoFqik6JFqikfj4fFqk6aFqkbR6Zkyn:QDjS4FDk6JFDkfjSFD6aFDbR6nn
TLSH T18021ED423A40143543A975B0D3462053B7EF7C1B32A7F9C8B8D686B0AC0D28DA3DCF96
Magika batch
Reporter monitorsg
Tags:Kongtuke ps1


Avatar
monitorsg
hXXps://roeerts[.]cfd/mfmop46p.js (ClickFucker) --> hXXps://roeerts[.]cfd/api/v1/session (token) --> hXXps://roeerts[.]cfd/api/v1/verify (gateway) --> hXXps://roeerts[.]cfd/api/v1/status (clipboard) --> hXXps://syshex6495[.]com/b (cmd)

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-11T16:45:00Z UTC
Last seen:
2026-09-11T17:01:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-BAT.Trojan.KongTuke
Status:
Malicious
First seen:
2026-09-11 17:54:55 UTC
File Type:
Text (Batch)
AV detection:
3 of 36 (8.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

PowerShell (PS) ps1 e5eba0c505759a2ddd4a03332caf54ee531a062dacf19c12c015221ab3065aad

(this sample)

  
Delivery method
Distributed via web download

Comments