🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1762e5986fbb593f5d917794646d4a12b03c6878a3f4e37a704e8b06a45fe382. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 7 File information Comments

SHA256 hash: 1762e5986fbb593f5d917794646d4a12b03c6878a3f4e37a704e8b06a45fe382
SHA3-384 hash: dee739d38847e173cb89124213eeb313cc06be7f07d9e34a833be1ff30c1ae9524812ee2c8026f759ba47f9a5b9bb29f
SHA1 hash: 92d8327e9196a5b6eb879f15117aa21fa036fd3c
MD5 hash: 3c180413e72cf7c9e9c951aa2d80d25e
humanhash: robert-low-gee-cold
File name:1762e5986fbb593f5d917794646d4a12b03c6878a3f4e37a704e8b06a45fe382.bin
Download: download sample
File size:2'287'611 bytes
First seen:2026-09-30 06:15:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:1QXr8nMhyDJZ3jPkHNW4Hux6la08juHNJqLckR:1Or8nMcDLbkHMQG6kPSicY
TLSH T1E5B53314DD69A0F55788789B4FADE89178F8A2B9F19F77B40CC85D5EAA803643833CC1
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Endermanch@SecurityScanner.exe
File size:2'330'112 bytes
SHA256 hash: 077c04ee44667c5e1024652a7bbe7fff81360ef128245ffd4cd843b7a56227cf
MD5 hash: 7dde6427dcf06d0c861693b96ad053a0
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
asprotect borland_c evasive installer-heuristic ntkrnl_protector obfuscated packed packed
Verdict:
Malicious
File Type:
zip
First seen:
2024-08-03T15:24:00Z UTC
Last seen:
2024-08-03T15:40:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Rogue.FakePAV
Status:
Malicious
First seen:
2024-08-02 22:24:05 UTC
File Type:
Binary (Archive)
Extracted files:
69
AV detection:
28 of 36 (77.78%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Launches sc.exe
Indicator Removal: File Deletion
Checks computer location settings
Disables service(s)
Executes dropped EXE
Stops running service(s)
Badlisted process makes network request
Modifies WinLogon for persistence
Malware Config
Dropper Extraction:
http://78.26.187.35/soft-usage/favicon.ico?0=1200&1=VYPMRCYQ&2=i-s&3=61&4=9200&5=6&6=2&7=919041&8=1033
http://78.26.187.35/soft-usage/favicon.ico?0=1200&1=BPDBRJCT&2=i-s&3=61&4=9200&5=6&6=2&7=926100&8=1033
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ASProtect13321RegisteredAlexeySolodovnikov
Author:malware-lu
Rule name:ASProtectv123RC1
Author:malware-lu
Rule name:ASProtectv12xNewStrain
Author:malware-lu
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 1762e5986fbb593f5d917794646d4a12b03c6878a3f4e37a704e8b06a45fe382

(this sample)

  
Delivery method
Distributed via web download

Comments