🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08417ee172bb264fa4bb4ab089e4a4b385180f58232b4dfbe4c35688acecc839. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 13 File information Comments

SHA256 hash: 08417ee172bb264fa4bb4ab089e4a4b385180f58232b4dfbe4c35688acecc839
SHA3-384 hash: f48c0dc76b7112c8ea3100c9f4b0f560165a7e6a7494a8c8b1c9b2400e844a2117ed6f2acf5899bf44008250fc27bc57
SHA1 hash: 5d02868f43bea2940bcf2ccbb1d4b1188771c709
MD5 hash: a6e0f7672f95e90c07a6eeec3b45bbee
humanhash: lamp-november-lactose-fix
File name:08417ee172bb264fa4bb4ab089e4a4b385180f58232b4dfbe4c35688acecc839.bin
Download: download sample
File size:14'174'694 bytes
First seen:2026-09-29 11:10:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:ExCbWglIbORr4NTjM/Cz90L6ZWfeQUiQKwDXisXcJD:iCXZRr4N8/+90mKeK02D
TLSH T129E633E11097EC5BA36B62249C1D4DC9E85D0518A4EB6A38C3CEF4D977C72D21138FEA
TrID 60.0% (.WMZ) Windows Media Player skin (6000/1/1)
40.0% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
US US
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:Tibia.exe
File size:3'052'032 bytes
SHA256 hash: e0206b49e7346b387d518f43182e4f170da2b5ea6ecc37aa72d1dcdc4bb6725e
MD5 hash: 98d04be30209e62fa5fd4b03caa31f6a
MIME type:application/x-dosexec
File name:minimap.ofmm
File size:1'309'972 bytes
SHA256 hash: 74564082da56a919cde15a0eb1d7bc38b04d1e67a1b78bb88f9c32512b2be5aa
MD5 hash: dba0a10b2155d8bb3f0e59da195c9b14
MIME type:application/octet-stream
File name:Tibia.dat
File size:263'909 bytes
SHA256 hash: 3fd515bf4558b9c152ec7240dd88f6a664cc4d1ae4d7f37698ff5c33e0f852ed
MD5 hash: 04c4444d5b552ef794e0bb81fd1cc354
MIME type:application/octet-stream
File name:Tibia.spr
File size:24'126'666 bytes
SHA256 hash: f893794dcf248e111812b363eb103b0edc8fab1f5f99eaf1b2d69e6af9790ad9
MD5 hash: 41ab0684bf9fe48b50432730e0d67f97
MIME type:application/octet-stream
File name:Tibia.pic
File size:1'369'172 bytes
SHA256 hash: 831fadcd14ee02fabb793c03f12f74ac8f9a32d1c2a754b8c346175488a6c911
MD5 hash: 3e33ab81abe00d16ccbedffdd3e9a33d
MIME type:application/octet-stream
File name:zlib1.dll
File size:69'120 bytes
SHA256 hash: 8cf3c0ed74ec8f89e49b4dedfac909d65060201d001fb8495fea3552641719d6
MD5 hash: 2da3fd99448760ea236947b0ca68a70d
MIME type:application/x-dosexec
File name:features.lua
File size:1'023 bytes
SHA256 hash: d445d79643e0335441342fc24b5964e08a588d2d498c642bf26ef2bc0b556b60
MD5 hash: ff8d198a5800b1bda643b2a34a2ae25a
MIME type:text/plain
File name:Tibia.otfi
File size:114 bytes
SHA256 hash: 8fe20df1dc5f7ab4f3e6e283fb4edf6be5114ec174c7ac6861557c7ea02d33c0
MD5 hash: 9a0efb43333598b61aa139baffd5c693
MIME type:text/plain
File name:installed.json
File size:1'965 bytes
SHA256 hash: 183f31f4d912fd04a94e49e02c402e91e80dd815e0f66e07e1ba3dc28bc413b0
MD5 hash: 56bc976f137dfa1b889d3cc62301328e
MIME type:application/json
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious use of SetWindowsHookEx
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops desktop.ini file(s)
Network Service Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 08417ee172bb264fa4bb4ab089e4a4b385180f58232b4dfbe4c35688acecc839

(this sample)

  
Delivery method
Distributed via web download

Comments