🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04eae0a7625bd280faee6cee1f09abaf77d278c16f4f4fae3c9cd607efbcb5a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 20 File information Comments

SHA256 hash: 04eae0a7625bd280faee6cee1f09abaf77d278c16f4f4fae3c9cd607efbcb5a0
SHA3-384 hash: f5faa60b0af848233cfdde5af07c7580157a5f91e8ec28977dd2fed0286ae0869809254f22462f571b6787067832c864
SHA1 hash: 273b880127e02cb317a95da16aebb5e6fd6969b3
MD5 hash: 60500852d9e75e4c7d839e9d50c37867
humanhash: seven-mars-texas-earth
File name:2026 List of Enterprises Scheduled for Tax Audit .zip
Download: download sample
File size:1'839'534 bytes
First seen:2026-10-07 11:31:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:HwLoznN1H3Mp6OTJwnGxvV+neHEcM6jxSFfhxEO:QLozN1HWbbV+enMQSth2O
TLSH T17985339859112FF7206A747593F548053F8741718EE08FAE9CB2B729501B6DE0E3BE2E
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
HU HU
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:updatedriversdk.dll
File size:2'827'656 bytes
SHA256 hash: 579aaff2d82c8230f645f7342266cadf45367d64db31988e0388dc2db1fd5847
MD5 hash: a828b160c0c6e83f4b672bf67faa1e42
MIME type:application/x-dosexec
File name:2026 List of Enterprises Scheduled for Tax Audit .exe
File size:1'589'696 bytes
SHA256 hash: 8f61eefe697a12fa7a3e5748910116359f74ae95b06a7ef6dc4429aac7b08bae
MD5 hash: 0ec0174e2053f72cb628c2ab2a07d50b
MIME type:application/x-dosexec
File name:_RDATA
File size:512 bytes
SHA256 hash: a4f2ecc5d1129534c49f6a9692306aa0ccb95fee59168eea2ed39a2cf23b853a
MD5 hash: 25ecba0520b4c5b4ff1408b77ed2838c
MIME type:application/octet-stream
File name:2
File size:381 bytes
SHA256 hash: 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
MD5 hash: 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug fingerprint microsoft_visual_cc overlay signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:WIN_Malware_PythonStealer_ForgeAuto_b24cb5bd
Author:Marjoriefort
Description:Detects PythonStealer (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_43faefd2
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_5001c94c
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_f1079127
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments