MALICIOUS — be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c.ps1
MALICIOUS — be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c.ps1 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Maldoc family. 6 of 50 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c - SHA-1:
937e75e0e1c82eecab69e9b8ad481bd7e0845308 - MD5:
c6f4df18cb880500f3921a179c3a3766 - ssdeep:
768:nzRraObp9Aps2zOX3+cLNqO5YxytVYGnH3h72MRDxjqP2QN77iyFMqXGrvfcQF:ndhUw/M5xOqgH52MDY2QN7HJ2r8G - TLSH:
T115340719B2A43EBFAADEBC81044942BDB4177BC662D1C87375D28F016C60D7369241FA - Submitted as: be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c.ps1
- File type: script · Size: 55877 bytes
- Verdict: malicious (95/100) · Family: Maldoc
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (6 of 50 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:credential-access
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: MalwareAnalyser community pack: TL_Suspicious_PowerShell_Download
- Microsoft Defender: Trojan:PowerShell/Boxter.PAD!MTB
- Emsisoft (Emergency Kit): CMD:Heur.BZC.PZQ.Boxter.1036.D1F05328
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Obfuscated powershell script: download, dynamic-exec, encoded-command, wmi, hidden-window, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Suspicious_PowerShell_Download (rule
TL_Suspicious_PowerShell_Download) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://213.145.86.112, 213.145.86.112 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://213.145.86.112
Embedded domains
- d.name
- ck.name
Embedded IP addresses
- 213.145.86.112
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report