MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0fca484a217a6b2c48595da7649de8a21c687efea516868ad019181f1ec8d1fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 10 File information Comments

SHA256 hash: 0fca484a217a6b2c48595da7649de8a21c687efea516868ad019181f1ec8d1fc
SHA3-384 hash: 1d45ec2d2a696b154d1e70ff44f95633b13f3f099cf17727f8215afc7cfd44cdac660f7daa58400fc62367b0928bb6f0
SHA1 hash: efc712ffd60c363f98a77d7d30e1fd0ab6ab7017
MD5 hash: 43d4d70e3b5ead6caa347a90f538d260
humanhash: tennessee-hamper-football-double
File name:DivineX.zip
Download: download sample
File size:75'650'122 bytes
First seen:2026-04-16 20:39:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: dx2026
ssdeep 1572864:fv2uMq4IfQj00hHunoau7WdXpB9ACdE3S6ptMjn0Zo5WwF:dMq4IQhHuL2WZ79AQCS6ptMj0Zo7F
TLSH T1BEF733641D27AFCDA8F9F5FC56B315C0608401178CE3ED4B2F9878F8ACA568EA1C6D52
Magika zip
Reporter burger
Tags:pw-dx2026 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
US US
File Archive Information

This file archive contains 59 file(s), sorted by their relevance:

File name:vcruntime140_1.dll
File size:47'264 bytes
SHA256 hash: e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
MD5 hash: 03b43160d21c08de07a79d0a1c5ee81d
MIME type:application/x-dosexec
File name:zone_map.bmp
File size:11'472'954 bytes
SHA256 hash: 5c1817aeee958457341d5292f7f3f0d6ce7f48bb92037478f97623dc9629858b
MD5 hash: 440f76d6aa31f24fa3a723a5e97fe1cc
MIME type:application/octet-stream
File name:partition_table.dat
File size:107'882 bytes
SHA256 hash: 7f2033ad299ac5b291a227e4675d7d5251e2881f6c83a3ad5b4605b95e1317be
MD5 hash: a498a898daddad25664ead99c209ef60
MIME type:application/octet-stream
File name:Qt5Widgets.dll
File size:6'167'552 bytes
SHA256 hash: f07780c6d003d0bea76f133a9e5ba4b612de0cb177358109f4ba87c8c66f305a
MD5 hash: 2946036619108a08079d2721df257269
MIME type:application/x-dosexec
File name:Qt5Gui.dll
File size:6'470'656 bytes
SHA256 hash: 7d734b80bc11f7ee84efc7fa02bcb458f8e1686282ae1aa0445da40fc8dff793
MD5 hash: 007f810bdd33dc64d1dc9f3e143997a0
MIME type:application/x-dosexec
File name:sparkline_bg_6a88e1.bmp
File size:12'194'754 bytes
SHA256 hash: 9841a6f4aa930cdd970c5a0ef897f93334626d250400b2e74ffba56bcb4dbc23
MD5 hash: dab935fbf80be812bd9f6f94c5ba4b83
MIME type:application/octet-stream
File name:vcruntime140.dll
File size:123'472 bytes
SHA256 hash: 184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
MD5 hash: 0d35c5e99871b4f02c490b9fd9dace34
MIME type:application/x-dosexec
File name:chart_bg_24af32.bmp
File size:8'963'694 bytes
SHA256 hash: b970baea212cc9da552b9b69ba1e213b55bfad9a5c5bb285f4ae08d213f31de7
MD5 hash: fe3a38ab2be43149a691a4eadaa6af55
MIME type:application/octet-stream
File name:content_layout.bmp
File size:11'840'850 bytes
SHA256 hash: c1412e4df54492d96ce1b40581ae1d3c06c23cdbb24446e7b4306efe787944e3
MD5 hash: 537b285dbc2ea199f179a2e08835c568
MIME type:application/octet-stream
File name:concrt140.dll
File size:309'632 bytes
SHA256 hash: 449e6073300d973d3d07f08896140ecdcc1c7fe8f58cff5aa7096cc124cf6393
MD5 hash: 046f9be1a19af1ed07d89f36c105ce30
MIME type:application/x-dosexec
File name:zlib1.dll
File size:136'648 bytes
SHA256 hash: 49f151535a5c3afa5ebfe4d3bb853948a942401c2c09ad1af52ae579b844eb6a
MD5 hash: 80755659eb4e1d7381c45dfe7d13969f
MIME type:application/x-dosexec
File name:msvcp140.dll
File size:553'552 bytes
SHA256 hash: def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
MD5 hash: 4e3fa9bd90ef020c14359639dc19312b
MIME type:application/x-dosexec
File name:tree_view_bg.bmp
File size:9'725'022 bytes
SHA256 hash: de0e837403a097a7cb162194fca470812d1ad6e7e9c9878ded3acced94b21694
MD5 hash: 78192f7d4ec98b13337d023253399cef
MIME type:application/octet-stream
File name:Qt5Core.dll
File size:6'130'176 bytes
SHA256 hash: aea8383f65307e0fb5f450c9b705363ad55c417eb240dc8633dab09c3dc348a4
MD5 hash: 463037c6f585124f08dc343b18c23bc2
MIME type:application/x-dosexec
File name:DivineX.exe
File size:378'008 bytes
SHA256 hash: a7479c3a4c702f2225a2ed343a8222bb36031f34474bf38d9a61f1a759fe3bf1
MD5 hash: 11fb8b77762947e113f6db67347b8633
MIME type:application/x-dosexec
File name:schema_catalog.xml
File size:1'220 bytes
SHA256 hash: 24b7b52271d6747ef70694d6345a4e3f568e405743bb35e0490df733b00ed855
MD5 hash: c66cd9343b94295c1af3fc62fe0e9fd9
MIME type:text/xml
File name:content_manifest_preview.xml
File size:5'283 bytes
SHA256 hash: 1c1732ba64bcab6c226c7b9988134b2f181f0d7cb06384b03af9a9636eedcfbb
MD5 hash: 3c47c588676e5435126b0feea92d5e30
MIME type:text/xml
File name:status_phrases.json
File size:2'560 bytes
SHA256 hash: 3c5c2afca0171a638ddcc17aefa413258ad271dd10cf8efe7bbefbb9addb884d
MD5 hash: 4dd272247a8362c5ae4b36009143132c
MIME type:application/json
File name:profile_manager_stable.log
File size:85'086 bytes
SHA256 hash: c6ebfdb639454baff8500d94fbbc367bfe56042c1f922d42996b09391dc2e1fd
MD5 hash: 5b2b09b655102eb2cf2b9a1da845e272
MIME type:text/plain
File name:descriptions.json
File size:2'399 bytes
SHA256 hash: ea09485a2424d96d68a186c334abfa4443bc7dc88e04ae048068cc4ff7b90605
MD5 hash: c033b94b8f93514bc84e698d4109ad0a
MIME type:application/json
File name:COMPATIBILITY_NOTES.txt
File size:6'023 bytes
SHA256 hash: f1b9ab9c10de2860e4bab8549ae896d520c3b1518a34a3b7d0969e41aedfab60
MD5 hash: 81e5fde70e16d845a750d210ccfa9a04
MIME type:text/plain
File name:tier_classes_stable.json
File size:962 bytes
SHA256 hash: 4820d7ee4450f7954685e7d956349438c01dc4a0c143254cff512a1bce5808d0
MD5 hash: 66153c3aba117d7571f43690aec13ff1
MIME type:application/json
File name:priority_map_beta.json
File size:2'851 bytes
SHA256 hash: e0423994ad744048ef0459fbd53bc19fa6795592b4fd1d59a48bdc5f80535a8d
MD5 hash: 4fe8c85ba87cd3a5855c30e2a5b648ed
MIME type:application/json
File name:event_journal.csv
File size:42'683 bytes
SHA256 hash: ffeadbcafed5ff867adfbbc53c62bfd1b5a9f8b572165fcd210019f65bf2b374
MD5 hash: 19dc4da9e73b5f177725dd3858447ab4
MIME type:application/csv
File name:architecture_brief.md
File size:3'324 bytes
SHA256 hash: 8bc706a8d4c4ec0cf9597f7e0ab88d868f7a4c83dc598d573a2e3c8c26eef642
MD5 hash: 6fd26dd15e1178b15f8dd6ca60a07cae
MIME type:text/plain
File name:profile_defaults_base.ini
File size:618 bytes
SHA256 hash: e776c4da7c49bd6bec18f5d22a3653330b87b03d3dbda9f53dd9f2c7f0c89a78
MD5 hash: 6dc451be78a736610e8f1b980b07653e
MIME type:text/plain
File name:role_definition.xml
File size:3'709 bytes
SHA256 hash: eb01e7ee86aec48351fc1461e42ebf4461455128e0bc41ce563cf790f9f15a2f
MD5 hash: 76ed7e96af04111e7c7c0df546185520
MIME type:text/xml
File name:action_prompts.json
File size:2'524 bytes
SHA256 hash: cfd78ad2737579c437c24884d62576a96bfb1df8ec0d769a78861e55ca3259dd
MD5 hash: 808df324929b4f789700da8a3b5b3675
MIME type:application/json
File name:alert_levels.json
File size:3'056 bytes
SHA256 hash: 7892a84e072a3f58e49e4ecdf83cb1f82b6daebbf7071b87b3671ae73227cee1
MD5 hash: 6d880abe4e7c7fd8596548dd1ee6651b
MIME type:application/json
File name:ui_captions.json
File size:2'040 bytes
SHA256 hash: c8c2cf7183513382c5ea9d08be74f73bf0906564671985497aed8cfa9e680c85
MD5 hash: db82c4d6bd1a38f18c0a581fdb3a26b6
MIME type:application/json
File name:alert_text.json
File size:2'860 bytes
SHA256 hash: 8c007114b91b2c51532b5392dfa96bbfe23ed483a438c9d1333f061db1db6f1b
MD5 hash: 6495e054b92a73ca9dd42068be5fad35
MIME type:application/json
File name:warnings.json
File size:2'067 bytes
SHA256 hash: c16af2ebeb78aa0ee02aa31cba9a08b6375a3b2674bc3198123007e3beb61214
MD5 hash: 9999e9e43e3b9881a5876fc20a67d043
MIME type:application/json
File name:cache_pool_stats_beta.csv
File size:26'598 bytes
SHA256 hash: ac3a0bc58cc102cc75366f0d51456414460e858d48edb807b1d6c81223494fa6
MD5 hash: 030ced8999b907aea59e6303e3126ecb
MIME type:application/csv
File name:migrator.log
File size:176'317 bytes
SHA256 hash: a3dfc8f2c8d26520ac507251e7858a679c9ca2e0325c24e1fd2e239d3d2bca3e
MD5 hash: 748c32615a1730c1f8e332a0de3dea5b
MIME type:text/plain
File name:ONBOARDING.txt
File size:2'910 bytes
SHA256 hash: 7bea2ca4dde3ed175648067a0ea0ddd0f9890e5aed677dce61fd34846918a483
MD5 hash: 55d665d331ccc92592862b313b3d4c53
MIME type:text/plain
File name:schema_catalog_legacy.xml
File size:4'156 bytes
SHA256 hash: 7fdc59586b653456dfd95f4adf4f14faa6e5f86955099e88d05bd6e62508adb7
MD5 hash: 3b6fb76d3df0a88151c083aba91777b0
MIME type:text/xml
File name:resource_budgets_fallback.json
File size:789 bytes
SHA256 hash: 971f514c40caec8f7beb6d2d00ea1a00460a880b4d187a4157b05739dae8f17d
MD5 hash: 9bb3370a55c41bfd211a7bb15bc5d4e6
MIME type:application/json
File name:field_names.json
File size:2'685 bytes
SHA256 hash: 186d19bf1622e9838d2c27996cefd3d25854f7cb028ad4aeb9591538e374fdb4
MD5 hash: c831b3afbda6c6dc191c931d8056ba75
MIME type:application/json
File name:hints.json
File size:2'225 bytes
SHA256 hash: 8f6f4bd64ef5bb725ce589062a16de0b16f77add02f9809a5ac7f246e036cd80
MD5 hash: 4a139d064925213bed937d0127a50e1d
MIME type:application/json
File name:display_prefs.json
File size:732 bytes
SHA256 hash: 53bacdca265264f3ab1c93c298663e6749c624cd97a0d85815e84690a5fe5d6b
MD5 hash: 5c644ef9af8fb800496ef96c03d6f0a8
MIME type:application/json
File name:renderer.log
File size:145'272 bytes
SHA256 hash: b64ab76af1694952717dfd5290b7c502f00b1274448a02dd90006469bfa23648
MD5 hash: 84ca84177738b76b5a9bc0a44517fc8e
MIME type:text/plain
File name:resource_budgets.json
File size:719 bytes
SHA256 hash: 47a29748465f9078efdade4b0adebff3220767a83cf8336548d570d03fc467cb
MD5 hash: 466b9c2093ec87d8546ebd32f1f5cafa
MIME type:application/json
File name:session_records.csv
File size:48'764 bytes
SHA256 hash: 02355f9b1ce400d0d325716ab103ec8ca685dc897e1f167a8e12ad5306b18859
MD5 hash: 622664052bfc86b154fecd820f30500c
MIME type:application/csv
File name:cleanup_config_override.json
File size:1'117 bytes
SHA256 hash: 3ce785a81b703074632a38e6c5e9a98c2b3891db1f6fbab37f1a0c87bf125790
MD5 hash: 9072d14750e229f816b86b0d64332f43
MIME type:application/json
File name:render_options.json
File size:2'857 bytes
SHA256 hash: 6bf8daea847b90cfae3063b33b304d6ea31934f546019a5b6b53fefebecccf80
MD5 hash: 1cef600bcb6beb2ac687cf3fc43123f3
MIME type:application/json
File name:RUNBOOK_beta.txt
File size:2'902 bytes
SHA256 hash: 22160e0ca7c1dc7d1aa10c0a05145d12bd8a2c9841a6eca1be0c9339b17d5d2b
MD5 hash: b62521cf0064f019ab5c0dd5ca96972e
MIME type:text/plain
File name:scheduler.log
File size:98'939 bytes
SHA256 hash: 1151075651fd36474540af76cdc1aa5680c7384a90a08459277e6857d7485197
MD5 hash: e743990163ad7f646d6ac0f450635a38
MIME type:text/plain
File name:baseline_guide.md
File size:2'940 bytes
SHA256 hash: c78d9d2b3283da8665a2f692c86600b44464c64855e103d9744a4bf6cbcceef7
MD5 hash: 39c4d493726b835cb19c0d8dd2894b3e
MIME type:text/plain
File name:pool_config.ini
File size:368 bytes
SHA256 hash: c939e1bc784cc2a38c495f5de5d4a979e544e7536fe77340fe1403087dfb2af6
MD5 hash: 3a6641db874aeb061f579049356fe2c3
MIME type:text/plain
File name:rebalance_log.csv
File size:45'929 bytes
SHA256 hash: 036f8f4b8b8fcf7234cc5db7381ed06aef1e4c98b4c820dc81d835b2fe634602
MD5 hash: d57947b94cea58dfdc46a98d46a10dba
MIME type:application/csv
File name:content_manifest_override.xml
File size:2'878 bytes
SHA256 hash: baccc64c5025925a88f97e77cf87a6e76800089b97218515dd8c355a78bc9835
MD5 hash: 7908117211bfa3cf02fcbcfc7d00a375
MIME type:text/xml
File name:compositor.log
File size:106'639 bytes
SHA256 hash: d34f220786412286e418058ebe4a4df8bdcf94d7fa974f55588a95d3a1bb3550
MD5 hash: 86ecf1a0a98a7c10687a36b94743a11c
MIME type:text/plain
File name:session_records_beta.csv
File size:39'410 bytes
SHA256 hash: 023239ec00b88309712fa701a5d8f10d824bc91c5b7a11c19123bb8ce8d6e3f1
MD5 hash: 6ee2b41f701443c692e384e5ad9e588b
MIME type:application/csv
File name:slot_quotas_override.json
File size:784 bytes
SHA256 hash: 1feaf7ab8a2dcf79971f1c17c13a4f3b84b6b0d52157b03e5d5db1b3f7578fb7
MD5 hash: e4ec15a2681bd7916786e2624eec6957
MIME type:application/json
File name:mod_inventory_legacy.csv
File size:30'571 bytes
SHA256 hash: 6086bcdd6558e2524908c7f72a99c6ac9c098b87801b4f57990207d1a796ad6d
MD5 hash: 40d713bf3c6e6f12c28ca5e12718be6b
MIME type:application/csv
File name:keybind_refs_base.json
File size:734 bytes
SHA256 hash: af6725bfd95a5693456c73704de7ef43647937ff05b31a3162b0c30a42e8ef02
MD5 hash: b3fead7c1d84cc8b0e3bc0f24bd9c89b
MIME type:application/json
File name:throughput_summary.csv
File size:31'101 bytes
SHA256 hash: a10e97d097c05fce752c28af07d494fb7bdf3a80b81eaf4f3eb6f2a33a68ba9e
MD5 hash: 1435ce7a50dd6ddb55314ea93376d4bf
MIME type:application/csv
File name:RUNBOOK_primary.txt
File size:3'721 bytes
SHA256 hash: 00d8a41be3587a7b42441b97ba2df0eba1851ae8566bdb22e86f63c0ae32ba49
MD5 hash: ff5e2cacc02079c0b9d8a13bd4f6635d
MIME type:text/plain
File name:theme_map_stable.json
File size:802 bytes
SHA256 hash: 7e421392cc107f0fe7ca234d6cb2c6c33840f23961a6aa895776773d3edeca69
MD5 hash: 8ca094c1355485e0bf79b472904627d6
MIME type:application/json
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments