🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1587129eeb17ffa030ee9068b0b4ecf32d6e095e085afbfc8724b84f08e0ee4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 10 File information Comments

SHA256 hash: 1587129eeb17ffa030ee9068b0b4ecf32d6e095e085afbfc8724b84f08e0ee4c
SHA3-384 hash: 77f048bba6f047ff40a49a999666786f3b43ef0d33ca6d9ae8cfdf3832ed7051986e7bef470adb1d75aa073aac9f4cdc
SHA1 hash: 7b912f8c683bc91a52634a7218a44ab2288ceb1e
MD5 hash: 85af75c2ea2564a29b3370f19a1bc4dc
humanhash: rugby-eleven-failed-california
File name:1587129eeb17ffa030ee9068b0b4ecf32d6e095e085afbfc8724b84f08e0ee4c.bin
Download: download sample
File size:20'554'908 bytes
First seen:2026-10-02 16:29:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:rSDWzot969TVP8Otl3AiGSZURIvpmeMXmv0ZcmWuhSFtaXcjvpIVfG6C/L5bSqAa:+DWzosTVUOtdUyOmycmWuhmdjvpIJG6A
TLSH T1E52733DFD0F18B9EF2636A190E59514CB2FF5748364C632D81E16A3720C21B77AA7187
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:海绵宝宝大战僵尸鱼.exe
File size:20'784'497 bytes
SHA256 hash: 2d6f357e943c488ccff769025c6c79a3edbbda510a5cea52def8e7c4cdc8d648
MD5 hash: 81dd4e9cb238a39d6d4d9b2269442d63
MIME type:application/x-dosexec
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug masquerade microsoft_visual_cc obfuscated overlay packed packed pyinstaller pyinstaller
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery pyinstaller trojan
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Reads the TCP/IP host and domain name from the registry
Drops file in Program Files directory
Drops file in Windows directory
Checks whether UAC is enabled
Enumerates connected drives
Network Share Discovery
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PyInstaller
Author:@bartblaze
Description:Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WIN_Malware_XWorm_ForgeAuto_6b06c990_Extrait
Author:Marjoriefort
Description:Detects XWorm (pe, etat extrait)
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 1587129eeb17ffa030ee9068b0b4ecf32d6e095e085afbfc8724b84f08e0ee4c

(this sample)

  
Delivery method
Distributed via web download

Comments