MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ec0910b0e3c4381b01eb1f64b2c686d00bba7d2db20cf1ce3d3d2d93e84932e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 3ec0910b0e3c4381b01eb1f64b2c686d00bba7d2db20cf1ce3d3d2d93e84932e
SHA3-384 hash: cb6ade52aed2c940300e733c3b11978477178e9a49bb0d2c4fdfe8d9142c5d5fad61bddc514ad2231732681b7f3be73e
SHA1 hash: 3b787fc3af7ab64e697c396112deccf9fe210dc4
MD5 hash: 800015d9aaf6338b5fe0a8f4de3bdcbe
humanhash: mountain-minnesota-undress-eighteen
File name:QuarkPC_V6.7.2.809.zip
Download: download sample
File size:28'908'117 bytes
First seen:2026-06-05 09:54:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:kpvsxpC4QiVeSwO93538JAhraPS+CMNorN3xIv8/SKD75Wco5/u+OPh5px3ylPu5:zC46Sv504GP3o34EmxPO55p8uy90Fcs
TLSH T1F65733DCD4A6CD473467BC3ABBF764E349246938FBC3AC6A6444629A74C63E446F3804
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:QuarkPC_V6.7.2.809.exe
File size:66'443'260 bytes
SHA256 hash: 9450d2520052b941f5e74116a1e593336c3a5706d3eef78bc6fc7ec8db2d9eea
MD5 hash: 38270c672b00cb37297138e691eb47c3
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
vmdetect cobalt
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm crypto crypto evasive fingerprint installer installer installer-heuristic microsoft_visual_cc obfuscated overlay packed packed reconnaissance xor-pe
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-06T06:34:00Z UTC
Last seen:
2026-06-06T22:13:00Z UTC
Hits:
~10
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery upx
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
UPX packed file
Enumerates connected drives
ACProtect 1.3x - 1.4x DLL software
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ZIP_Smuggling_Jun01
Author:delivr.to
Description:ZIP archives with data smuggled between last file record and the central directory.
Reference:https://github.com/Octoberfest7/zip_smuggling/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments