Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
b6a016ef240d94f86e20339c0093a8fa377767094276730acd96d878e0e1d624
SHA256 ⚠ 3 PULSE HITS
↓ CSV ↓ JSON
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH 55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
20/30
3 pulses
VIRUSTOTAL
35/35
27/76 detected
ABUSEIPDB
/25
IPv4 only
URLHAUS
0/10
NOT LISTED
General Information
Hashb6a016ef240d94f86e20339c0093a8fa377767094276730acd96d878e0e1d624
File TypeFileHash-SHA256
AlienVault OTX Analysis ↗ View on OTX
3
PULSE HITS
Pulse Hits 3
Indicator Type SHA256
Threat Level
ASSOCIATED PULSES
PULSE NAMEDATE
Behind the CAPTCHA: A Clever Gateway of Malware 2024-09-24
Nanocore - Affected 2025-11-08
ACTIVIDAD MALICIOSA | Relacionada con Lumma Stealer 26-09-2024 2024-09-26
VirusTotal Analysis ↗ View on VirusTotal
27/76
DETECTIONS
MALICIOUS
Malicious 27
Suspicious 0
Harmless 0
Undetected 36
Reputation 0
File Name a.ps1
File Type Powershell
File Size 0.3 KB
TOP DETECTIONS
VENDORRESULT
ALYac Trojan.Agent.GNFW
AVG PwrSh:FakeCaptcha-B [Drp]
Arcabit Trojan.Agent.GNFW
Avast PwrSh:FakeCaptcha-B [Drp]
BitDefender Trojan.Agent.GNFW
Bkav W32.Common.7D62A71D
CTX powershell.trojan.generic
Cynet Malicious (score: 99)
ESET-NOD32 PowerShell/TrojanDownloader.Agent.JHG trojan
Emsisoft Trojan.Agent.GNFW (B)
URLhaus (abuse.ch) ↗ View on URLhaus
✓ NOT LISTED No malicious activity found in URLhaus database.