MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 403a92e9c295b50cb429a7f4bcdf9ad0bb749a49be9d196e8a9192cd0cc15dd8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 403a92e9c295b50cb429a7f4bcdf9ad0bb749a49be9d196e8a9192cd0cc15dd8
SHA3-384 hash: 082a96d7b33642590f44a779116821f1c59b60b889f9cf7a9100a7ca7b6e1565ff82a95a12c7e53c3bbac9745c767dce
SHA1 hash: e5ee2f532353520c85cf2bbe39912c5a044fae0c
MD5 hash: f7175f360f05234691674f0ab9601c77
humanhash: violet-uniform-fix-aspen
File name:ReleaseNah.zip
Download: download sample
File size:22'550'711 bytes
First seen:2025-07-31 09:41:32 UTC
Last seen:Never
File type: zip
MIME type:application/x-rar
ssdeep 393216:5k1AKUpKpcXqSPY+Z9+o0uUZXyM9rWXR3QlngmSKjvUsK28OUL6NDUUjXPv+0F0:5k1lUpKpMLN9+oWtDu32g4kb6NPrVF0
TLSH T1CE373362A74355AEDB2D69EC36E43F59022AFD31C5103AA4D44ECF78DCDF2F0A888525
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter burger
Tags:zip


Avatar
burger403
hxxps://www.youtube[.]com/watch?v=lOAQk8INjgM -> hxxps://sites[.]google[.]com/view/skeet -> hxxps://href[.]li/?https://hidesploits[.]com/ReleaseNah.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
NL NL
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:storarc.dll
File size:1'300'528 bytes
SHA256 hash: 264a886f1d79df9a993a9f3ecbfb2f8dc93e823606bec279281a52206da8e1cf
MD5 hash: 70ec10365fc79be2a2becc453878dad0
MIME type:application/x-dosexec
File name:ssleay32.dll
File size:348'208 bytes
SHA256 hash: d84d5356636ec304fe258f3956ca260b81d92d9564e42c916da202f87c6f9fc6
MD5 hash: adab5cb87403f0bf558a5dfdbce71701
MIME type:application/x-dosexec
File name:storelib.dll
File size:166'128 bytes
SHA256 hash: 539d92876caaff1bdfc592bdc5affb2a3e1053e477cecb43f790b77517afa7a4
MD5 hash: aab3abafa0621df5e03e897b82aa1e61
MIME type:application/x-dosexec
File name:ReleaseNah.exe
File size:76'421'211 bytes
SHA256 hash: 9e6a062646a88e2e7aa08b3f664f9c6dfad10654f96ea3d970d44a14cc70fb84
MD5 hash: afb3a9fa914dc9002e3ddeb4eb9a3799
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc crypt
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
fingerprint microsoft_visual_cc signed
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
.Net Executable PDB Path PE (Portable Executable) Rar Archive
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 403a92e9c295b50cb429a7f4bcdf9ad0bb749a49be9d196e8a9192cd0cc15dd8

(this sample)

  
Delivery method
Distributed via web download

Comments