MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48c3854a498d317a6c0c080fcf3524a92b4f3832f0fdd9481818deaff1153c46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 48c3854a498d317a6c0c080fcf3524a92b4f3832f0fdd9481818deaff1153c46
SHA3-384 hash: 6ca4cd32fa0f618461b1c98f61d20f12ee946f0e27c590c19e3f00684e075a701cf264b33b01037f9c61c1604178be48
SHA1 hash: 8a4d27b1a12761aad9dc9d5e2927fc330dffc552
MD5 hash: c4c8ea8f8b4f7dfec9619ebb15fb9f74
humanhash: snake-bacon-west-violet
File name:dllfo3
Download: download sample
File size:17'068 bytes
First seen:2023-07-08 10:51:48 UTC
Last seen:Never
File type:unknown
MIME type:text/plain
ssdeep 384:NJ9RBXhmfn55zAQU/Ceap6VRxswrSGwxGRSZhyEZKmx/tF+3M7HucY:f9bXhmf55WCFYR2wHwQRS7yZW/zv7HG
TLSH T1DA720A3A5D23FCC06FBF3D8494183D922C987E378B755268FEC508961CA6550EF1B5A8
Reporter JAMESWT_WT
Tags:91-213-50-74

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated
Result
Verdict:
MALICIOUS
Details
Base64 Encoded Powershell Directives
Detected one or more base64 encoded Powershell directives.
Threat name:
ByteCode-MSIL.Trojan.Zusy
Status:
Malicious
First seen:
2023-07-08 10:45:25 UTC
File Type:
Text
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

unknown 48c3854a498d317a6c0c080fcf3524a92b4f3832f0fdd9481818deaff1153c46

(this sample)

  
Delivery method
Distributed via web download

Comments