MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59
SHA3-384 hash: 01b4aa36b2123b3c733695140ae1e9668fe9463e159c71f8049dc920df9ed6379080d0353db384dd8031070f251a52fa
SHA1 hash: ff46b2146781484909271f1e214b86249ec9dd16
MD5 hash: ad98bec0fe9e779451cdefceb457c9b1
humanhash: winter-ink-cold-magazine
File name:10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59.py
Download: download sample
File size:25'561 bytes
First seen:2024-09-19 05:47:27 UTC
Last seen:2024-10-10 16:18:34 UTC
File type:
MIME type:text/x-script.python
ssdeep 768:Tujc50hSLUDwM0RXhpSFsR90IgRuxaj8sUVl7N:T13UDwNRVBB
TLSH T1C2B2A7917AA65936D363C42F99628483631F3C2349195C38F6ECD7E06FC5A3183F26E9
Magika python
Reporter JAMESWT_WT
Tags:95-164-17-24

Intelligence


File Origin
# of uploads :
2
# of downloads :
104
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
fingerprint masquerade
Threat name:
Script-Python.Trojan.NukeSped
Status:
Malicious
First seen:
2024-07-15 22:28:32 UTC
File Type:
Text (Python)
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_decoding
Author:iam-py-test
Description:Detect scripts which are decoding base64 encoded data (mainly Python, may apply to other languages)
Rule name:Detect_APT29_WINELOADER_Backdoor
Author:daniyyell
Description:Detects APT29's WINELOADER backdoor variant used in phishing campaigns, this rule also detect bad pdf,shtml,htm and vbs or maybe more depends
Reference:https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties
Rule name:golang
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments