MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 19e5eca388c115a901371dc3a488357b09b45cf0131a3732f960b0c61dfd76d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 19e5eca388c115a901371dc3a488357b09b45cf0131a3732f960b0c61dfd76d5
SHA3-384 hash: 917da9e8b7efa845c59d9d68e9544d317d703a42a318cffe96006fd0663e86d7fabffdc5044725d6960df09a2f5eb039
SHA1 hash: 2045e59ce58c8285e0e703f1c7586018aa743611
MD5 hash: ffdfca015b988c521bfc359ba042eed1
humanhash: fish-mike-butter-paris
File name:app-64.7z
Download: download sample
File size:88'914'323 bytes
First seen:2026-07-26 11:39:28 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 1572864:de4hdV6xfFj7Hv59nFt90c3Hkc7M0zLr1X3OznfxySo3RPqSlfVDWTzN:de4DoxfdLh9nF7z3V7vl385ySor0TzN
TLSH T10E183305C99A087FC63DF539D9E3F26983968C9BD660F168056BD7DEAE21F0E948400F
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter JAMESWT_WT
Tags:7z Windows-Update-Assistant

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments