MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 495111e2591171e474a815e040b4587d11d5e977a15e7113580de3fcfb9ac31f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 495111e2591171e474a815e040b4587d11d5e977a15e7113580de3fcfb9ac31f
SHA3-384 hash: d9be7e5959553b321390787a9fcce852df9e5f32ecd67a8fdb908e720b43315fb425f32f9733131876fb108ed373a078
SHA1 hash: f305843a059e5147d5fdafefa5e96fead746998b
MD5 hash: bf2e3ed27f2685294dcba25c3fd9abc6
humanhash: early-wisconsin-sink-winter
File name:dllF3
Download: download sample
File size:17'068 bytes
First seen:2023-07-08 10:52:01 UTC
Last seen:Never
File type:unknown
MIME type:text/plain
ssdeep 384:XJ9RBXhmfn502AQU/Ceap6VRxswrSGwxGRSZhyEZKmx/pGfQ6ucg:59bXhmf50FCFYR2wHwQRS7yZW/so6u
TLSH T1627209365D23FCC06FBF3D85D4183D952C947A33CFB552A8FA8908962CB6550DB1B8A8
Reporter JAMESWT_WT
Tags:91-213-50-74

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated
Result
Verdict:
MALICIOUS
Details
Base64 Encoded Powershell Directives
Detected one or more base64 encoded Powershell directives.
Threat name:
ByteCode-MSIL.Trojan.Zusy
Status:
Malicious
First seen:
2023-07-08 10:45:25 UTC
File Type:
Text
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

unknown 495111e2591171e474a815e040b4587d11d5e977a15e7113580de3fcfb9ac31f

(this sample)

  
Delivery method
Distributed via web download

Comments