MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 56a666601e66a01cc8dcb53a470d9ea092633c76197cd13919c7749e51ebccbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: 56a666601e66a01cc8dcb53a470d9ea092633c76197cd13919c7749e51ebccbc
SHA3-384 hash: d6884e99316965151f64240ae825cc5dbd4d8934fe97694198c39e10ec182d3bc2529193621422c589497b8ad44dba8c
SHA1 hash: d042afa59dd81cc9e0d0e50e3cc8694a3c5f8fb4
MD5 hash: 785028ccb1763c504626d3678a0c8fe7
humanhash: delta-violet-early-zebra
File name:56a666601e66a01cc8dcb53a470d9ea092633c76197cd13919c7749e51ebccbc
Download: download sample
File size:1'490'119 bytes
First seen:2024-12-17 17:24:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:/o20He/zYHE7f3q+tpA/Pw6ZVeKvyNK69z8wT31mhIC2wGfuEkLmGHHhMh:qHeUAf6GAXw6ZjvsW+fC2wGIxSh
TLSH T199653367CE5BFD62F0C47430F60C287AD956A45F4B06F6435D89C272ACF2910BA9E2C6
Magika zip
Reporter JAMESWT_WT
Tags:com-atokyo-News zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
IT IT
File Archive Information

This file archive contains 8 file(s), sorted by their relevance:

File name:main.scpt
File size:10'372 bytes
SHA256 hash: e3f8abd06d91204c46cbafaf5038807b3d236caf64727dd06e975a589c471284
MD5 hash: ff15427d45b84e79b2e81199613041bb
MIME type:application/octet-stream
File name:applet.rsrc
File size:362 bytes
SHA256 hash: 2a3e0d7724ae605a189fe5aebdbab2d172e64a471e82264bed509d72d75a3442
MD5 hash: e774b812081217a5a3f2284566d8978c
MIME type:application/octet-stream
File name:applet.icns
File size:1'498'535 bytes
SHA256 hash: 0cb0166c72c0f74f285f74adc682a70796b37ee5af79cf767bc43c00afa22e3e
MD5 hash: e8eecb0033be1a4918c647dfb44ae46c
MIME type:image/x-icns
File name:applet
File size:134'144 bytes
SHA256 hash: c7c6ef735941e8d4fbc92629fc9310f14a896c7f7c21043ae65ec6cf70c60b7a
MD5 hash: cba88a3f4d77aa51f94f0a1a076cb909
MIME type:application/x-mach-binary
File name:Info.plist
File size:2'611 bytes
SHA256 hash: 91908405d6be0944799c0e642d78d97a5bb85fa015c7f1ae66042ac93b330e88
MD5 hash: 880e030a90d4a9ab9649cbbfc846784b
MIME type:text/xml
File name:PkgInfo
File size:8 bytes
SHA256 hash: 412d70757c4fdecdd73355ac4bb3ba80c6705110d15cfbc9fe925e7b4faf7962
MD5 hash: db6f4017a24d2cb070ad3de12adb78f4
MIME type:text/plain
File name:TXT.rtf
File size:144 bytes
SHA256 hash: 3945f89f68e96845dc1787ef63c47dadbd242eaef37d0866353628fd46bf561f
MD5 hash: cf46f759a582d5aacb8c53894d8240a3
MIME type:text/rtf
File name:CodeResources
File size:3'454 bytes
SHA256 hash: 85133c829f0f22b1ca904c20a5a07ac538c8503e4f95bb5c87361021b9174c05
MD5 hash: bc88d494c589e18dfd7c985865b3497d
MIME type:text/xml
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-09-01 08:38:10 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments