URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as PowershellEmpire.

Database Entry


Signature:PowershellEmpire
Firstseen:2024-04-23 05:48:05 UTC
Lastseen:2025-08-23 10:51:14 UTC
Unique Payloads:10
URLs:9

Payload


The table below shows all payloads that have been identified as PowershellEmpire.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-08-23 10:51:1493fbf17f966abe2ffcd2680a95a383e35ec85c07a86b53536afc2c4581346c915'313Virustotal results 35 / 62 (56.45)
2025-08-23 10:51:095ebc77efec011b34f58c7b421307e002793174f895b16a1acaa65f0a5f9393df5'353Virustotal results 30 / 62 (48.39)
2025-07-05 13:30:39aeb74ef2d68a80544f5f5b86047f6a72c6a223509fe1db31e7e69cfb691b4de17'590n/a
2025-07-05 13:30:35debd6aab3904e6a12fc740ce2eca4625d9a0db9f2fbfde4ba791772fc8876eea7'778n/a
2025-04-27 19:27:0412217d3c32c89defc8d8187ead17ae2077b968163bafe0d70e687295623c676d16'672n/a
2025-04-27 19:27:042daba930a1e86237dfdc296d02d8e915ff98231f500a505c75dff3448a2028ea7'592n/a
2024-09-27 09:25:386ffba5bb0f914b60c67f7640c7858454cbe405e44d9a84c241dbb3d084a3dcda2'471n/a
2024-09-22 10:34:064902bf5124af3916e10e71a064ba1f31a39222d6b169cb6dcde866b6f510bc4c2'482n/a
2024-09-22 10:27:05f195a69b9d907599214eb5a4dec75388acc2161d62397a0b40d2c422e16274582'478n/a
2024-04-23 05:48:0502745be1221b455aa03a5faf6629d156bfeb6c457c80c0151fd8562b8c89eecd137Virustotal results 0 / 61 (0.00)

Number of entries displayed: 10 (max: 1'000)