MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4edddd66b6178ec78af28bc437eaa675319fbcb0e83a7f5b6eebe42c543e6372. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4edddd66b6178ec78af28bc437eaa675319fbcb0e83a7f5b6eebe42c543e6372
SHA3-384 hash: bdd7e22b9032116f597daa268322a56c8ebe2785a1b04ab0411ef261ec49a2c3885460297d5d2fba74ab32570f08cd59
SHA1 hash: 3e9a4a53a5d515ab385aaf07cbda96f28b2c66a9
MD5 hash: 9ab8c3a9c3438eacdb43e3c6ec9b163c
humanhash: saturn-echo-glucose-early
File name:app-64 (3).7z
Download: download sample
File size:84'310'879 bytes
First seen:2026-07-26 11:42:35 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 1572864:ZrziNx5qlpvenpSeA5MR8TIHzFV7w2rOs5FkDgRPx:0x5qlEpHdTzbhis53H
TLSH T19B0833BAFBBC1022D84994B953C084A45FCEC0754E97E4F4F568926FAF536C0EE21627
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter JAMESWT_WT
Tags:7z Windows-Update-Assistant

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
7z
First seen:
2026-07-26T10:11:00Z UTC
Last seen:
2026-07-26T10:15:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.Generic
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution persistence spyware stealer trojan
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments