MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57a91106d35878b14c089e87e4aae9df85aed2875bfa2bcd2e13df8ad397cc67. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 13 File information Comments

SHA256 hash: 57a91106d35878b14c089e87e4aae9df85aed2875bfa2bcd2e13df8ad397cc67
SHA3-384 hash: 4327725dca0fa2d736bbdac8d142e8a51ed2635875545cfd70c2fada945d5f2645a8fa14e58d0ff2c5b19884c5e2a0e5
SHA1 hash: 3aa6d39c174b4ef7922448ce32d34278df5be809
MD5 hash: e8c92d1e3812eebcc8422d0e4afa58c2
humanhash: papa-charlie-echo-may
File name:Please verdict - dos meses - 30200 - 09.12.24.zip
Download: download sample
File size:737'726 bytes
First seen:2026-08-12 07:48:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:u1uYuhjF/0Td6EKoO1CCQzxQCrCuWun2uf7K6AvHaG9X0h9dTQZP60yg5B4IeCMK:u1bTLQE/xQyxK6AvHat/EP/r569juwIz
TLSH T188F433A54B5886B0B224981BF7FE88B4F8AD804FEF524756F9469605B53F0FD01B71C2
Magika zip
Reporter Anonymous
Tags:zip


Avatar
Anonymous
URLScan from infected system -> CSV

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
CA CA
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Please verdict - dos meses - 30200 - 09.12.24.csv
File size:4'739'727 bytes
SHA256 hash: c3bebbff9e57e640178494d9d73eae1bf5859fe6edad062dea89dd6262d2a910
MD5 hash: 6f59246ca9494707668efa2f33acf9b9
MIME type:text/plain
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
CSV Office File
Payload URLs
URL
File name
https://account.mi...
CSV Raw File
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-vm
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:NET
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:test_rule_vldslv
Rule name:virustotal
Author:Tracel
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments