MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 226cd36c2d1f002651aa8a4fcd20cb589029ec5605b2e256cac8472d4cb33d2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 226cd36c2d1f002651aa8a4fcd20cb589029ec5605b2e256cac8472d4cb33d2a
SHA3-384 hash: ab9b5e25d9b5f2edf619a3baec6d9964083c697baf551318999e8c74013efff78a82846ffe902a0d3b4f6e126a9e03b2
SHA1 hash: 1c1af3fd54e99c284b295170ff50b49da45be050
MD5 hash: 8d048b90aa51c16bc0702d879836ec09
humanhash: uncle-equal-ack-magnesium
File name:Solidworks-2026-5.29.8653-latest-win-x64.msi
Download: download sample
File size:101'376'000 bytes
First seen:2026-06-13 12:03:41 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 1572864:nLG7z8LsUTEmZ1IRCPcLW4c3s5b77AEx51E5MpNO/zXEMCfYGRwUBZkvKnOR:wc7Ym1PcL40f7Tx5S5YOTQYy5kvkM
TLSH T15A2833727112DC77C28C793D5299273EE431AF519B2480E3E95A359F0F31792AE381AE
TrID 98.2% (.MSI) Microsoft Windows Installer (454500/1/170)
1.7% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter SquiblydooBlog
Tags:msi signed

Code Signing Certificate

Organisation:Elusive Techno
Issuer:Microsoft ID Verified CS AOC CA 04
Algorithm:sha384WithRSAEncryption
Valid from:2026-06-05T20:04:16Z
Valid to:2026-06-08T20:04:16Z
Serial number: 330001bad6b5201f995e297c3700000001bad6
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 79feca9d0b1d90c4db7f5fcf166b1d89b959469fc51ef51bdb177b01966f407f
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug CAB crypto expand expired-cert expired-cert fingerprint fingerprint installer installer keylogger lolbin overlay packed reconnaissance revoked-cert short-lived-cert signed wix
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery persistence privilege_escalation ransomware revoked_codesign
Behaviour
Checks SCSI registry key(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Windows directory
Badlisted process makes network request
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments