Verdict
No source reports this indicator as malicious. That does not prove it is safe: it may simply be new.
- VT_ZERO_DETECTIONS No VirusTotal vendor flags the indicator.
Key indicators
- SHA256
- 7600ffe12da441fe89d035b13801e8e91d064bc544a27b19a5cf49f6ab8b18f5
- SHA1
- 613000dc53e7ef0b048021f68dd06c101994da29
- MD5
- e65ecca3754249c00f50a035202f7591
- File name
- PowerShell.EXE
- File type
- Win32 EXE
- Signature
- Not signed
- First submitted
- 2026-07-14
- First seen
- 2026-07-14 (77 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| No vendor flags it (0 of 75). | 0/75 | 0 days recent | Benign |
Coverage · checked, no record: MalwareBazaar, ThreatFox, AlienVault OTX, Code signature, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineUnknown: nothing links this indicator to malicious or benign activity.
Attribution
The evidence does not establish who operates this indicator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
All evidence
6 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| No vendor flags it (0 of 75). | 0/75 | 0 days recent | Benign | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| Code signature | No record. | — | — | No record |
| No record. | — | — | No record |
Engine rules applied
- VT_ZERO_DETECTIONSNo VirusTotal vendor flags the indicator.
- NO_POSITIVE_EVIDENCENo source provides malicious or benign evidence; absence is not proof either way.
Analyst summary
Consistent with engineUnknown: nothing links this indicator to malicious or benign activity.
Attribution
The evidence does not establish who operates this indicator.
Key indicators
- SHA256
- 7600ffe12da441fe89d035b13801e8e91d064bc544a27b19a5cf49f6ab8b18f5
- SHA1
- 613000dc53e7ef0b048021f68dd06c101994da29
- MD5
- e65ecca3754249c00f50a035202f7591
- File name
- PowerShell.EXE
- File type
- Win32 EXE
- Signature
- Not signed
- First submitted
- 2026-07-14
- First seen
- 2026-07-14 (77 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
The evidence does not establish who operates this indicator.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
Evidence timeline
- 2026-09-29VirusTotal: No vendor flags it (0 of 75)
- 2026-09-29Investigated
Recommended next steps
- enrichDetonate the file in a sandbox outside IOCSCAPE.
- huntFind the parent process and delivery path on the host.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

