🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0507f067f172fb4d8d152d360b362ae0de6d6fd77c4c8f4c6c1560c875b5a4ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments

SHA256 hash: 0507f067f172fb4d8d152d360b362ae0de6d6fd77c4c8f4c6c1560c875b5a4ff
SHA3-384 hash: 9778c55cd1e398e345ca013e4f37012a375f750f2524dd5d5558711dcc9a8fa15ec44ab4ca9dc6006c021807a9ce31f9
SHA1 hash: 9fa1b399e17b5c79883b24a7c7feff4b1ae5bab9
MD5 hash: 9d6f9af0db3a2c612b634a1f769a8dd5
humanhash: nuts-lactose-wisconsin-florida
File name:0507f067f172fb4d8d152d360b362ae0de6d6fd77c4c8f4c6c1560c875b5a4ff.bin
Download: download sample
File size:7'742'816 bytes
First seen:2026-09-29 15:36:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:4XquhpDBT10r5JKvPC18313VbdxyxLneZs4psUp48YnWLNkh7VtUiU2Vp6RAwUND:4awTCPH1wHdxKUzjpwWEU7CERAGpm
TLSH T1E27633FE26845081EF03A474415AEDC390C697AF439EFAEC35FA2B0D0DD696C219D91E
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
US US
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
SVG Zip Archive
Threat name:
Document-HTML.Phishing.Generic
Status:
Malicious
First seen:
2026-09-29 03:31:36 UTC
File Type:
Binary (Archive)
Extracted files:
160
AV detection:
4 of 36 (11.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
adware discovery execution spyware
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:flashakacoder_kit
Author:Lenny-3BO
Description:FLASHAKACODER PHP banking kit -- operator tag + admin chain + Telegram exfil + HTML form-action
Reference:hunts/flashakacoder-tarrarat-cluster
Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 0507f067f172fb4d8d152d360b362ae0de6d6fd77c4c8f4c6c1560c875b5a4ff

(this sample)

  
Delivery method
Distributed via web download

Comments