MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8 |
|---|---|
| SHA3-384 hash: | 936f081f243395cc7c52a21683d1e755e3f08efb93a84e757366b4c42f8e2e690a0638b7b770eda3b9a2a3e46e7186bb |
| SHA1 hash: | f5d89e872c18e66fad8a20bdd42bc82fe0a28096 |
| MD5 hash: | dd601199638787b40d41243a05a5923c |
| humanhash: | ceiling-idaho-social-alaska |
| File name: | xw.py |
| Download: | download sample |
| File size: | 4'334'869 bytes |
| First seen: | 2025-07-07 07:48:29 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-bytecode.python |
| ssdeep | 3072:Wcq9oC185DroCRjFC5wv1abYYx98w955gCDf4qx5fY1FduHDtx5C5eG98w9owg5F:WcqT |
| TLSH | T16B16182EB356BF93BA45D085D52EE7B541B2983A5CB5F001B96CF5A2001BE39E8113CF |
| Magika | pythonbytecode |
| Reporter | |
| Tags: | py WsgiDAV |
Intelligence
File Origin
# of uploads :
1
# of downloads :
42
Origin country :
ITVendor Threat Intelligence
Verdict:
Clean
Score:
99.9%
Tags:
n/a
Verdict:
Malicious
Labled as:
Trojan.Generic
Verdict:
Malicious
Threat:
Script-Python.Packed.Kramer
Threat name:
Script-Python.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-19 12:21:54 UTC
File Type:
Binary
AV detection:
12 of 24 (50.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.