MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8
SHA3-384 hash: 936f081f243395cc7c52a21683d1e755e3f08efb93a84e757366b4c42f8e2e690a0638b7b770eda3b9a2a3e46e7186bb
SHA1 hash: f5d89e872c18e66fad8a20bdd42bc82fe0a28096
MD5 hash: dd601199638787b40d41243a05a5923c
humanhash: ceiling-idaho-social-alaska
File name:xw.py
Download: download sample
File size:4'334'869 bytes
First seen:2025-07-07 07:48:29 UTC
Last seen:Never
File type:
MIME type:application/x-bytecode.python
ssdeep 3072:Wcq9oC185DroCRjFC5wv1abYYx98w955gCDf4qx5fY1FduHDtx5C5eG98w9owg5F:WcqT
TLSH T16B16182EB356BF93BA45D085D52EE7B541B2983A5CB5F001B96CF5A2001BE39E8113CF
Magika pythonbytecode
Reporter JAMESWT_WT
Tags:py WsgiDAV

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat:
Script-Python.Packed.Kramer
Threat name:
Script-Python.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-19 12:21:54 UTC
File Type:
Binary
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

13c524903e578ea10ea026c06267d8f47fcd9c249f4dc7d3cce773d5e60b8be8

(this sample)

  
Delivery method
Distributed via web download

Comments