🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3df42b6f82cb5ae54a014acf2ad5a137bd0821310cbd23c06009b5419ecb3693. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 8 File information Comments 1

SHA256 hash: 3df42b6f82cb5ae54a014acf2ad5a137bd0821310cbd23c06009b5419ecb3693
SHA3-384 hash: 2443ba7b88bd83e438d24a07bbabed096a65d70cd7e95bb5d1c1190043a4634bac3b9fd6caf27cbba1c1e772f8a04754
SHA1 hash: 02640babba6a592c83dc745d3e8f462a89e45a7f
MD5 hash: 40b80637dfbd89cb5f4e90f74ec12341
humanhash: lithium-oregon-winter-july
File name:3df42b6f82cb5ae54a014acf2ad5a137bd0821310cbd23c06009b5419ecb3693
Download: download sample
File size:541'353 bytes
First seen:2026-06-22 21:59:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:p4lhhLoVDI2FLmMJKreqO3g/ALyYG0ZaDajTCXMO8xzDOeDBV:2xopIAmMJjA/f0Za6TCXKBxFV
TLSH T14FB4237B0A7F70D00C6A43BA8B468611A43D9D621628AFBD47DCE6CC8D0E51EBF14E5D
Magika zip
Reporter johnk3r
Tags:213-176-73-130 EtherHiding github-com-Nightizi stealer zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
CH CH
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:resolver.exe
File size:771'584 bytes
SHA256 hash: 3200b7d6a42fc8d2bf213cd17b1bd6f0fc76c4f626330ec6fb0a3f9a0ef9e00e
MD5 hash: a643386d4af0ce1d488dbcaaa393a2d4
MIME type:application/x-dosexec
File name:App.bat
File size:29 bytes
SHA256 hash: a96ffc9f649333f9e84b7a7e1101cf85f7a5f143253db1d7853e6e48d46b3c72
MD5 hash: 6763da0e8a0778b62bd2bc404bfa1e1b
MIME type:text/plain
File name:icon16.txt
File size:296'308 bytes
SHA256 hash: 33250ded61c43128b6c29b01de7b1cc962b241b236933f54bc42b648afae2398
MD5 hash: 8d818e3923c032d9bc233ef67be430fe
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
virus agent core
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug fingerprint microsoft_visual_cc reconnaissance
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-22T12:37:00Z UTC
Last seen:
2026-06-23T17:42:00Z UTC
Hits:
~10
Detections:
Trojan.Script.Agent.mlfa
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2026-06-22 16:46:10 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Capability_Embedded_Lua
Author:Obscurity Labs LLC
Description:Detects embedded Lua engines by looking for multiple Lua API symbols or env-var hooks
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 3df42b6f82cb5ae54a014acf2ad5a137bd0821310cbd23c06009b5419ecb3693

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
Padawan commented on 2026-06-22 22:24:46 UTC

"method": "eth_call"
{
"to": "0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc",
"data": "0x3bc5de30"
}