🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 143bf4866461a98e05b0b0ea3d68dcbf070bf98f65e8627890d070591bb4b41f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Guildma


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 143bf4866461a98e05b0b0ea3d68dcbf070bf98f65e8627890d070591bb4b41f
SHA3-384 hash: e4a49804c6978fb5c31a4ee8aa4673ae2c5713d34ff29ef248d234fe80517fcdc9b26408b9071dc5138a8f45ad3c0981
SHA1 hash: 9397fe0ce9dcd93bb970cbaad0eeaf63d5fb300b
MD5 hash: e6035add513a58ba3cef324d0ebfb403
humanhash: magazine-tango-victor-july
File name:solicitado52.zip
Download: download sample
Signature Guildma
File size:56'285'037 bytes
First seen:2026-10-07 21:03:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:jQTQ9IaQzqN6exP3/PJSqP1nGf1TxL/4p:kc9szEx3BSqPUf1TxL4p
TLSH T142C7337662AB9ABC2FC837197C5B904CA88F6349CC541B05F0DE9E2C4B12587B177EE4
Magika zip
Reporter johnk3r
Tags:Astaroth banker contabilidadeacportela-net controedatoerpestanavidroslat-com guildma hggdconfeccoesgruponacional-click saladeouroriopreto-shop zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
BR BR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:solicitado52.msi
File size:56'369'152 bytes
SHA256 hash: d082bed899d8f975f201975f3c0517debd094cf40630649283de097b0361b8fc
MD5 hash: 9766a65884177f26090aeca0a6247865
MIME type:application/x-msi
Signature Guildma
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
MSI File
Payload URLs
URL
File name
http://ocsp.digicert.com0C
MSI File
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug expired-cert fingerprint installer keylogger reconnaissance signed
Verdict:
Malicious
File Type:
zip
First seen:
2026-10-07T20:11:00Z UTC
Last seen:
2026-10-09T08:15:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-10-07 21:04:29 UTC
File Type:
Binary (Archive)
Extracted files:
38
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Guildma

zip 143bf4866461a98e05b0b0ea3d68dcbf070bf98f65e8627890d070591bb4b41f

(this sample)

Comments