🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fc87c91bb369dee0b58a52eb5bc17753cc9a3598d553fb8bd86e8f5c19229a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 17 File information Comments

SHA256 hash: 2fc87c91bb369dee0b58a52eb5bc17753cc9a3598d553fb8bd86e8f5c19229a6
SHA3-384 hash: de5f90998335ddedef771e45d4a67e1e5aa0936874c4f87d77e6345d734e896fcba53a6e1f2a81b5fb88c8842413db6b
SHA1 hash: 1365fb592873934b8e0c307b73329d606468a92d
MD5 hash: 9bf9345a211e4d1ca6262a8d508c3292
humanhash: white-princess-friend-wyoming
File name:Tax-202609070119.zip
Download: download sample
File size:2'457'937 bytes
First seen:2026-09-11 09:34:05 UTC
Last seen:2026-09-11 09:34:19 UTC
File type: zip
MIME type:application/zip
ssdeep 49152:8YnvktU4knkt/rHltsb8UynLqICc0X1xAi1euEGsABA:8kvktUrkt/A84IQ1cVGsA2
TLSH T124B53391D725F4F80CF85125BB650B67B2B2CA5B32931D2BB2817D0410F30EED99E69E
Magika zip
Reporter cocaman
Tags:zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
42
Origin country :
CH CH
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:hdp_elev_shim.dll
File size:38'400 bytes
SHA256 hash: 8cf64ffbecb9bf4e73b37a6680b4c50d3da672c8382bdb9c1ea4d5901822195d
MD5 hash: e4060b8c0563b9a3724d4752228c004e
MIME type:application/x-dosexec
File name:Tax-202609070119.exe
File size:1'942'000 bytes
SHA256 hash: 4bfa832e0b5d59d5498d85071020167e97b06c69aa43cca2cfccd0c91d535c1d
MD5 hash: c7d924f8b54c44e1edaa87f9b280bf39
MIME type:application/x-dosexec
File name:nw_elf.dll
File size:1'928'935 bytes
SHA256 hash: f586d4c364cfc479ccf6348512e1acae73169fde71a9fe502bc59637322cc7f4
MD5 hash: 2ee801e9eb55563fc1a4e85a34bf6667
MIME type:application/x-dosexec
File name:2
File size:381 bytes
SHA256 hash: 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
MD5 hash: 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-11T08:55:00Z UTC
Last seen:
2026-09-11T09:01:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery evasion execution persistence trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Adds Run key to start application
Identifies Wine through registry keys
Windows security modification
Looks for VMWare Tools registry key
Enumerates VirtualBox registry keys
Looks for VirtualBox Guest Additions in registry
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender Real-time Protection settings
Modifies Windows Defender TamperProtection settings
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_VBox_Guest_Additions
Rule name:Check_VmTools
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:test_rule_vldslv
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments