MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 579b8d0e88983ef08a2db7ff531b66b4f71b72e86d6ef6557dcab11c145e9643. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 579b8d0e88983ef08a2db7ff531b66b4f71b72e86d6ef6557dcab11c145e9643
SHA3-384 hash: 2510345085561d758c53fb01d1988154057b1407b9350dd4d78cac74e123841e2ebdefd6c8c4dfb889539c42c8d15468
SHA1 hash: 352505b1ead415b4391d7244d09f22773ee43fe5
MD5 hash: 05cd3835bbd922f81d7c460282defa8c
humanhash: monkey-lake-summer-maryland
File name:579b8d0e88983ef08a2db7ff531b66b4f71b72e86d6ef6557dcab11c145e9643.zip
Download: download sample
File size:51'896 bytes
First seen:2026-07-21 14:42:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:jpGyf7WOnScGDvBoyPGGSxygAORe9ei86c0yOiK1VyRvT:j8tOnSRvBoyP9S4q6VnylT
TLSH T1EB33F9F7B280BDF9987901F48EFA8F8A11542D164579D888DC2AD5FB4F22A94ED3044F
Magika zip
Reporter johnk3r
Tags:33-224-205-92-host-secureserver-net banker FakeCaptcha zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
CH CH
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:LEIA-ME.txt
File size:741 bytes
SHA256 hash: ef5981e8824437d9bb7534f7c72a76f85891f622cb0bfdc2b194261253873593
MD5 hash: 10377e2d4e9a9f01901c6230f448340b
MIME type:text/plain
File name:data_ab8754.xml
File size:321 bytes
SHA256 hash: 1ab507b64b055e3a5b37d668c205246d37ef76c8bd9ab89c6dd469db7e9e0293
MD5 hash: 6ee0ee0a59b42eb6c3379c36238173b6
MIME type:text/plain
File name:data_f3919e.txt
File size:321 bytes
SHA256 hash: 898cdd9a4a9a2993211f9c6c908d52e7a2b9012436c0e8e7d974eef45c7d299c
MD5 hash: 739dc9552d2949dcef6ef579f151f2d0
MIME type:text/plain
File name:data_82d8ab.txt
File size:317 bytes
SHA256 hash: 8898b54288bee43dcb930b4a826aebf334ca775a2e862aed41c53dd314258d3b
MD5 hash: bd6c2eaa347baf8f4e76e278f3315cc5
MIME type:text/plain
File name:data_80e603.dat
File size:323 bytes
SHA256 hash: 05dff2295b2172557867f9fcb685ed2cd5ca7a96551ab8c278b4a70456dc84f4
MD5 hash: d276d8380de26b831364bc79e2a1b0a3
MIME type:text/plain
File name:manifest_8366d7.xml
File size:705 bytes
SHA256 hash: c0b36269d11521128b3683adb915e71f07506a07408ecb498a3f5b69d42e8452
MD5 hash: 40b53d24f182e5cbf387f8fca1c5ac69
MIME type:text/xml
File name:data_03d082.cfg
File size:325 bytes
SHA256 hash: bbccd4e405bb1cbc77e424430c43c35a2291ecfd139e5a24d6205417bdcf8838
MD5 hash: 118536cedf94f7de376448b0571bbb99
MIME type:text/plain
File name:Agencia_Tributaria_КомпПак_5391.hta
File size:46'679 bytes
SHA256 hash: d6cfaeff2e0f834a78baec45f68594f4321abf26ba389807e701fc6b26e0c85f
MD5 hash: 7594e0552499f0fd2de0d1e63695fb06
MIME type:text/html
File name:data_9e5d80.xml
File size:314 bytes
SHA256 hash: bd64fa9211be8c38e88da1727ba4831da7aa487b892eeaee75405d10fa1cf0fa
MD5 hash: 1629dda73acb1faf1acb93b3e5181060
MIME type:text/plain
File name:component_42e5da.xml
File size:434 bytes
SHA256 hash: dceacb3261910097038e33e144200fbbc6f0fa90e4da4d015f58486c69ee9214
MD5 hash: 8fded29fc6b7b7aa62f9ca2f6a48d3f1
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Base64 Block Contains Base64 Block Html Zip Archive
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-07-17 22:36:16 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Script User-Agent
System Location Discovery: System Language Discovery
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments