๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35f031359ee5f45d7a6385194fb282e1834f955b5b1b2ecd9b5c8dcbeb68c81d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 22 File information Comments

SHA256 hash: 35f031359ee5f45d7a6385194fb282e1834f955b5b1b2ecd9b5c8dcbeb68c81d
SHA3-384 hash: 53294c95bd9a5c7b2f028b163117a53712c47cff4a38d68fd6ed6c89673e7fae141af0872cce1fb53fba0c211c6156ac
SHA1 hash: ce61e256e1ea7d97ecebb32f1a7f6ef9c2198868
MD5 hash: 3eef222775abe3de125709b6c260e54e
humanhash: beer-bulldog-october-sweet
File name:nox-fleet-spotify.png
Download: download sample
File size:9'696'867 bytes
First seen:2026-09-23 12:56:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:oagt2vTjqDyLgbbUcmLeK5ewpiOQCULvvEX7hgQ9vmUtGHR43glCS6s2CzrRjof:4t2vTjqeuzmV5FpiOoLvvs2UvNgHR43v
TLSH T19DA63341D275308520306E2553025CE06F4BBEDDD8F2ECE39AF95A6B72C84D95ECAEE1
TrID 60.0% (.USDZ) Universal Scene Description Zipped AR format (generic) (6000/1/1)
40.0% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
FR FR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:rename.exe
File size:17'232'384 bytes
SHA256 hash: d74ca37af3e73bbaf6b88201aba801a3aa4dbbb51221e8bf89609293a3de14c7
MD5 hash: 99917edcac7e4cea1b7e7d090e0cc10f
MIME type:application/x-dosexec
Vendor Threat Intelligence
Result
Verdict:
Suspicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-23T12:11:00Z UTC
Last seen:
2026-09-23T13:39:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.PSWStealer
Status:
Malicious
First seen:
2026-09-23 12:57:29 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks BIOS information in registry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_Promethium_MaliciousPacker_20211202
Description:Detects Promethium Group MaliciousPacker
Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments