🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20a1307e28e1c4fa6cc7e69fcf62cd750e746ed9c2a41f5bff21b275283b76be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 20a1307e28e1c4fa6cc7e69fcf62cd750e746ed9c2a41f5bff21b275283b76be
SHA3-384 hash: 0008099bc5df94e10274d25b9b4e63dc4e7f7533e79f8b5ccec33e7ea5f76e13d5dfd3ee8e10132aa43b4dca5c76664d
SHA1 hash: cf9448a6d68e773ab385f909efdddc1028def5c0
MD5 hash: 43f66a618b31ff8d58f4729fb5de1e56
humanhash: east-sink-violet-seven
File name:windows_7_professional_sp1_march_2025_(x64)_pre-activated.7z
Download: download sample
Signature Amadey
File size:15'081'731 bytes
First seen:2025-03-21 20:17:15 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 1787
ssdeep 196608:q9GgZfMqZTodnZEVpLTvLD2Di1tvtESUAaplGALl//eAMOHJAXy3DeO96Fs1zxy7:q9NZf9odYu21/93ai6l//XJY4ets1zQ7
TLSH T156E633EFF243E9EB261445A32AFC8115D7D9021464F0C1D73F1A66BB42AF169CC285EB
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:7z AutoIT file-pumped LummaStealer pw-1787


Avatar
iamaachum
https://media.cpirep.online/Windows_7_Professional_SP1_March_2025_%28x64%29_Pre-Activated.zip?c=AHzE3WcvYwUAbnwCAEVTFwAMAAAAAAAL => https://arch.cpirep.online/k/zip/S8r8ZXh6pE6Q0TkmUXLmHgd3/Windows_7_Professional_SP1_March_2025_(x64)_Pre-Activated.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:windows_7_professional_sp1_march_2025_(x64)_pre-activated.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:885'280'718 bytes
SHA256 hash: 5e0302299c699f8c3d1ce9a2b3ecbd2847b2f536f39a22d6df60a41774ea8792
MD5 hash: a56da90b93ec1d9fe2d7b0f7859cd415
De-pumped file size:302'592 bytes (Vs. original size of 885'280'718 bytes)
De-pumped SHA256 hash: c5f5dd45da839b429fc85e8da6b370a56d19ec2dc0a4858878dbe0f7a4404fd3
De-pumped MD5 hash: c6e1358120b1c14f2f77c694c0f236d4
MIME type:application/x-dosexec
Signature Amadey
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
infosteal master shell sage
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

7z 20a1307e28e1c4fa6cc7e69fcf62cd750e746ed9c2a41f5bff21b275283b76be

(this sample)

Comments