🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4894d0c747c5fa618e629226304dacef2bfa2935ced2fb07f26c76cef43675b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 26 File information Comments

SHA256 hash: 4894d0c747c5fa618e629226304dacef2bfa2935ced2fb07f26c76cef43675b7
SHA3-384 hash: 267d17b905a1e254a6c3bc524e7d07c21cfda77da65e1e4188dbab2dcfc70b851af95a2085d4f4a8a2790a3e065cc4fd
SHA1 hash: 873becacda722655f6990ddc14072804073da06f
MD5 hash: c3ced4ac86cbd57e108c4e61e7889b1c
humanhash: spring-iowa-crazy-chicken
File name:puma.zip
Download: download sample
File size:11'557'047 bytes
First seen:2025-10-30 07:19:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:0Qyiv52g7CKrAqcLrixQYRO5kpB295kmfIExZJ8Ll5RjXdKfaNUU1M2Z3:ByUP7CKs+RO5kj2DgEvJIl5RjXd7UL25
TLSH T17DC6335F60FB2E83E10BF1350691F516B927E68CF48510B33A454B6368C39795AF2A2E
Magika zip
Reporter JAMESWT_WT
Tags:WsgiDAV zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
IT IT
File Archive Information

This file archive contains 38 file(s), sorted by their relevance:

File name:_wmi.pyd
File size:39'768 bytes
SHA256 hash: 6793bd216b5a329689cde8b1532858d6731707ec5063897f979a81e57077402c
MD5 hash: f94e8c9a440cdac95d2f69a9045d937f
MIME type:application/x-dosexec
File name:vcruntime140_1.dll
File size:49'776 bytes
SHA256 hash: 6a99bc0128e0c7d6cbbf615fcc26909565e17d4ca3451b97f8987f9c6acbc6c8
MD5 hash: c0c0b4c611561f94798b62eb43097722
MIME type:application/x-dosexec
File name:_socket.pyd
File size:86'360 bytes
SHA256 hash: 7acc6c44436bf77be3c425d39f0acba03b42119513ef9db31a7039c969e056bd
MD5 hash: 659d1aa860099428669dcdae9c7ab661
MIME type:application/x-dosexec
File name:_asyncio.pyd
File size:73'048 bytes
SHA256 hash: 166206ce4d432931cb29d8ee7398edf84b1b751d694668e0c89fff65f4147657
MD5 hash: 71d61bee0232c5918455cc0e0df77e76
MIME type:application/x-dosexec
File name:_ctypes.pyd
File size:134'488 bytes
SHA256 hash: b9c9e713f11e111daa55e4a62a135d7e385fa7aa0986d30b286d000e122b13aa
MD5 hash: 1606ace764f2b3ca8ab20cada221cf56
MIME type:application/x-dosexec
File name:pythonw.exe
File size:104'280 bytes
SHA256 hash: 960d4e036ac0d01a5a092ad0f7ac192b821e4e70ccecfe0cb443967bf8e22897
MD5 hash: d8a10c3b3d531a8f7d0615e9cb04914f
MIME type:application/x-dosexec
File name:_queue.pyd
File size:35'160 bytes
SHA256 hash: baa5a4cec6c369efc461f7109f1e6150c0afeef8ce53dbd9d673a00093cdadf8
MD5 hash: 24bd30234b4fa243007ac061bd7bc8a5
MIME type:application/x-dosexec
File name:_uuid.pyd
File size:27'992 bytes
SHA256 hash: a004b7f5b07333db6c7079244c3880d57aae4bdfa56bde8bca2c530dea824cd2
MD5 hash: d4ed5f1a9dc9d9871aedd4b4bf55fe77
MIME type:application/x-dosexec
File name:_decimal.pyd
File size:283'984 bytes
SHA256 hash: b1f2dd16190154652f9ddb9e58a335932f56674dcdf6395bc634c577ae00429c
MD5 hash: 7290e69c43dd5f7813cfcd9d2b5e5fd1
MIME type:application/x-dosexec
File name:_elementtree.pyd
File size:137'048 bytes
SHA256 hash: 951e2623208ee402825f574041944cb9de2c67a9671c2cac607c1c22cd6da31a
MD5 hash: 436e76488b4b127ab426b70744c12517
MIME type:application/x-dosexec
File name:_hashlib.pyd
File size:69'464 bytes
SHA256 hash: 1e079c6b44488e273bc62d9bcb27cec519e9916b47b8c2878ebade0772e0f484
MD5 hash: 82c0261589ab1c473c765d3ff36f9f8b
MIME type:application/x-dosexec
File name:libffi-8.dll
File size:39'696 bytes
SHA256 hash: eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
MD5 hash: 0f8e4992ca92baaf54cc0b43aaccce21
MIME type:application/x-dosexec
File name:python3.dll
File size:72'536 bytes
SHA256 hash: 9b179a9e44badc9c9d327182996040c87be183ad4c9469645280ed3e4a2d7694
MD5 hash: 04ba59ed5314652ec779f1389900913e
MIME type:application/x-dosexec
File name:_multiprocessing.pyd
File size:38'232 bytes
SHA256 hash: ce2b76029e1d4a3d4248bfe786277c6118f284e713bd2ba275d1288690e5aac5
MD5 hash: be69dbf62064930c2d3ddb38fe5dd11f
MIME type:application/x-dosexec
File name:wel.bin
File size:629'506 bytes
SHA256 hash: 797152e9527c9d9a146321c3aa9dc6bd937dcf99027de765b062ea125188c1b0
MD5 hash: 6f3e82af2de357f502b9f308107e38da
MIME type:application/octet-stream
File name:pyexpat.pyd
File size:215'896 bytes
SHA256 hash: 922dd767c7a27065d2a8bd08f151bfcf22f92b25e9abdf981297960f7587d650
MD5 hash: 2a23d9e46ba8bf1473aa5a3092efaf55
MIME type:application/x-dosexec
File name:_bz2.pyd
File size:86'872 bytes
SHA256 hash: 64d9fbb516e08a6780dca160e40d8c6723d2a659b5ca3020de7a041305b3a3d4
MD5 hash: 7098611e0258f8bd1ed5ecb971c88763
MIME type:application/x-dosexec
File name:vcruntime140.dll
File size:120'400 bytes
SHA256 hash: 052ad6a20d375957e82aa6a3c441ea548d89be0981516ca7eb306e063d5027f4
MD5 hash: 32da96115c9d783a0769312c0482a62d
MIME type:application/x-dosexec
File name:libssl-3.dll
File size:794'992 bytes
SHA256 hash: 1e4bc0638682bfcbb36f4465d6a2e9944d917a60f05ecc8ddf9e96847e05e13f
MD5 hash: f31ed8154564b75e48f2525a7e9f5742
MIME type:application/x-dosexec
File name:_overlapped.pyd
File size:57'688 bytes
SHA256 hash: 8f40faaf55ce040ff5027a23df21da549e7d22a590832e47f6ce75a54a6134e5
MD5 hash: dee520ce483b5f301ebe6e510b9caa9b
MIME type:application/x-dosexec
File name:_zoneinfo.pyd
File size:50'520 bytes
SHA256 hash: 4d0d790eb40e033dbc114f95f04b24e49b17e902aee66755e345c2b0c6fc7d28
MD5 hash: 9d9ba95134ef71a76fe05c8d572e85b0
MIME type:application/x-dosexec
File name:python.exe
File size:105'816 bytes
SHA256 hash: 08a64dc73ac3e3776b49f0097c6306bdb9c8f7990a037065213324d328467bf5
MD5 hash: 77741743ba390fa911613c0f4e93b1e2
MIME type:application/x-dosexec
File name:_ssl.pyd
File size:182'104 bytes
SHA256 hash: 738c579ed151498337026ea1f5dc7688197b41b74e39f4d9de05261bb35d9206
MD5 hash: 359e1c3e69044b4283223783ca406b95
MIME type:application/x-dosexec
File name:libcrypto-3.dll
File size:5'229'424 bytes
SHA256 hash: e03dd02fdcfb791981c9962827cfcf495f2a47a514c1526efb57f847a9df514a
MD5 hash: 8e8f32ae40518478e44269cf22cf4399
MIME type:application/x-dosexec
File name:sqlite3.dll
File size:1'584'984 bytes
SHA256 hash: a8236fc65f202eb8a98bd4397b39cfaacc2771ff4d765acadef0abf91492dcd3
MD5 hash: 4b0784a2b965b2df34711c1e66ea50ca
MIME type:application/x-dosexec
File name:select.pyd
File size:33'112 bytes
SHA256 hash: 01c8fef709b657b17e1db3754b05cb1070ad3e303dd531ef0f5545316df53aa2
MD5 hash: c13138061da04f3fc3cd44c9fd3b9db0
MIME type:application/x-dosexec
File name:winsound.pyd
File size:32'088 bytes
SHA256 hash: f019f208df5f531b17ff91ba1a7e5aaa56567e0a38f2c99e8c391aacde87b03c
MD5 hash: 63d8f51135d94c328e7fa0b9ffada432
MIME type:application/x-dosexec
File name:python313.dll
File size:6'125'912 bytes
SHA256 hash: c9f98606d0d06f4e8ae75ae385021e58b57c90d4fd325c0313c8c42abe1ebf63
MD5 hash: 48edb6a0be2bfee5b83e2c31675511e5
MIME type:application/x-dosexec
File name:python.cat
File size:569'886 bytes
SHA256 hash: 275a686addc6d068fa35215cc75d42492d4e407416c87682c578eeaede214eb4
MD5 hash: 5c173bfd5eb89ee3946132f11c3096b7
MIME type:application/octet-stream
File name:unicodedata.pyd
File size:712'024 bytes
SHA256 hash: cc1f066d88c26a21808ec6053c0989d702b6d46429bb4f363e4f29b67f311c89
MD5 hash: daa6555238f525d8070b07484085a3b9
MIME type:application/x-dosexec
File name:_sqlite3.pyd
File size:130'392 bytes
SHA256 hash: 48672a5c55ca7d0cda0e05e9b00201f3aff791bea79604e671d4e0b25cfb5dbe
MD5 hash: 6eb0061a11b55dc793a82acfd39c29fe
MIME type:application/x-dosexec
File name:_lzma.pyd
File size:159'576 bytes
SHA256 hash: 999ba26fe0b0376b7898d50ddb2f5012e7a64228e31fcdca99a4d7079df669e3
MD5 hash: b7100b8fb3c579c848d8960b927d322f
MIME type:application/x-dosexec
File name:h.txt
File size:78 bytes
SHA256 hash: 7aabdbf405d57617e1a2f76ef846ae4686a62a4aaedda594fdd77e3daf4bac88
MD5 hash: c22e14d43487d98f44801268afaeae9b
MIME type:text/plain
File name:python313._pth
File size:80 bytes
SHA256 hash: 35ddf94682ff9aa713a8d63557242ad00f3f28fdd39337f02c3bda4c0f791577
MD5 hash: c23ad35e55e5b1a71ee2e9dd97723749
MIME type:text/x-objective-c
File name:python313.zip
File size:3'785'301 bytes
SHA256 hash: c3036ffd9a1a0121d9cfbc705513c9965b41da9db5c9c54491be7eb181d58acc
MD5 hash: cc5a2c88db1909172f5679b3e28ae439
MIME type:application/zip
File name:inf.py
File size:10'139 bytes
SHA256 hash: ac75746a6cf31efbd113e9d1852e5b7c58cf0865bd04270d228bf25b8a4b9f4f
MD5 hash: 8e4d79d3395bede394f93370c7a0d365
MIME type:text/plain
File name:2
File size:1'349 bytes
SHA256 hash: 13160d8e413f8a06f47aec8b20edc6ea5d63b63190f77ae9a1ec1bed7195da79
MD5 hash: 7ef51f60309aa7899efdfed89aa1ad6f
MIME type:text/xml
File name:LICENSE.txt
File size:33'861 bytes
SHA256 hash: 62bec384df47b0328307db41455ff6ea2559e5546b394ac69148561b21703120
MD5 hash: a1eed141ca8c9e45c8e85f8387c2e6f2
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm expired-cert microsoft_visual_cc short-lived-cert signed
Verdict:
Malicious
File Type:
zip
First seen:
2025-10-29T12:40:00Z UTC
Last seen:
2025-10-31T06:52:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2025-10-29 18:28:17 UTC
File Type:
Binary (Archive)
Extracted files:
1179
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_decoding
Author:iam-py-test
Description:Detect scripts which are decoding base64 encoded data (mainly Python, may apply to other languages)
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CAS_Malware_Hunting
Author:Michael Reinprecht
Description:DEMO CAS YARA Rules for sample2.exe
Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 4894d0c747c5fa618e629226304dacef2bfa2935ced2fb07f26c76cef43675b7

(this sample)

  
Delivery method
Distributed via web download

Comments