🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2da46ae5dbabc6442cc0d2698725dae918befa9f192992f58ebbebd4ac3e2888. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 2da46ae5dbabc6442cc0d2698725dae918befa9f192992f58ebbebd4ac3e2888
SHA3-384 hash: e7b11dc29bbd6ff74ff2c871d26aeb2d09e02b7ec3d2765c318cfd59b665d43cd7f4d57e4e9168790be5b058cd6c3923
SHA1 hash: bc7db5296c662d5f81b1c29db91b63040e545a5d
MD5 hash: 4cbafb288263fe76f5e36f1f042be22d
humanhash: white-single-mountain-east
File name:t.zip
Download: download sample
File size:4'379 bytes
First seen:2024-09-16 16:33:48 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 96:VTEcuNIbUfnfgnrNJno8wcB7uUjRD1j8e7FO:VYcCI6ArN5o4BaSg
TLSH T14B915D6C6514DF88CC6E7B3385ED178674B4701CE0036F6B50286196F85B7F1AE41739
Magika zip
Reporter JAMESWT_WT
Tags:64-49-14-181 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
IT IT
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:xS023.tmp
File size:1'120 bytes
SHA256 hash: 963af57641c094df6b5656552daaafd5ced0a1435261e612a4640604d023ebca
MD5 hash: 1a1723be720c1d9cd57cf4a6a112df79
MIME type:text/plain
File name:xM568.tmp
File size:2'094 bytes
SHA256 hash: c4aba442d881cfa112fe3a6b1d2381b089cbe163828cfdb2d57abba95737a07d
MD5 hash: 0c3fd7f45688d5ddb9f0107877ce2fbd
MIME type:text/plain
File name:07578.tmp
File size:904 bytes
SHA256 hash: 40c9f86e343f5a54570162bcca2d18f046d65c310d3ccfe975a2c2c31c5c47cb
MD5 hash: 73ed9b012785dc3b3ee33aa52700cfe4
MIME type:text/plain
File name:R9147.vbs
File size:502 bytes
SHA256 hash: 5356b49086c693e6effdc73978fa63c0f191978b401e128bef8e248db1544e75
MD5 hash: 12386be22ca82fce98a83a5a19e632bc
MIME type:text/plain
File name:s.vbs
File size:1'604 bytes
SHA256 hash: b7fc11f37433b4f1d357e43b5a26802a96f5f043f70289360d60b12d6248e5ea
MD5 hash: 622358469e5e24114dd0eb03da815576
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
Execution Stealth
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
kimsuky persistence powershell
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-09-16 15:57:46 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Malicious_VBScript_Base64
Author:daniyyell
Description:Detects malicious VBScript patterns, including Base64 decoding, file operations, and PowerShell.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments