🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 615861fb801e8b04c847598db4e1e46e4b046295017caa37cb5486dde72b5865. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 24 File information Comments

SHA256 hash: 615861fb801e8b04c847598db4e1e46e4b046295017caa37cb5486dde72b5865
SHA3-384 hash: 9d19cebb5c2cc3ddf268e818f4c906dc6be29bbac1dfd7c3f0aaf130e3b9bb23cd59897a05019a7e6be36e69572612bd
SHA1 hash: 91140593e10492b38a3c089fcd7943f3f268a5de
MD5 hash: f34996cc1f44c98729ef6ce92d05e41c
humanhash: potato-mars-hamper-double
File name:p.dat
Download: download sample
File size:11'098'289 bytes
First seen:2026-09-11 17:30:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:+K6kmLhoon8UWVDxxaniXA4m9ZCrnNfqMD2Tb1TRkp2v5atKmRLmpjNM1tdSV+m2:KL686onie+f2tTRkpc8tRfzUV+l
TLSH T1B5B63372C1744FE2C26D80764B317A461711EA6194C9CF19CDAE95F70C3A9FA4B32A8F
Magika zip
Reporter skocherhan
Tags:batab-dev-files-nyc3-digitaloceanspaces-com zip


Avatar
skocherhan
https://batab-dev-files.nyc3.digitaloceanspaces.com/media/p.dat

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
GB GB
File Archive Information

This file archive contains 36 file(s), sorted by their relevance:

File name:_wmi.pyd
File size:39'416 bytes
SHA256 hash: 4f6361517b4e127642d4e641ddbfa060b3d32da8ac7fc7a35a51c02680933084
MD5 hash: 39fca3cd9a98b14c4e47225ee28063d3
MIME type:application/x-dosexec
File name:vcruntime140_1.dll
File size:49'744 bytes
SHA256 hash: 82a2f9ae1e6146ae3cb0f4bc5a62b7227e0384209d9b1aef86bbcc105912f7cd
MD5 hash: 68156f41ae9a04d89bb6625a5cd222d4
MIME type:application/x-dosexec
File name:_socket.pyd
File size:85'864 bytes
SHA256 hash: 961dc7c65a28c174688e2f6b7803a615b9c034849a17cfc6527a27ccb2eeadb0
MD5 hash: 20631cd0c1477f9b0d3897fa61ef749d
MIME type:application/x-dosexec
File name:_asyncio.pyd
File size:74'088 bytes
SHA256 hash: e79dcc4ee292a9b93143674c3509743ef0496fd32e53c55b93f13cc402f815e5
MD5 hash: a577ff6de2add83120127061d7c294a8
MIME type:application/x-dosexec
File name:_ctypes.pyd
File size:127'848 bytes
SHA256 hash: ed4170b2c2c302639301a01c6aac4c5575e6e4c936edc803d3ba6c34444e35e1
MD5 hash: fc2da679024ed27f02ecd1b05cf14cda
MIME type:application/x-dosexec
File name:pythonw.exe
File size:104'304 bytes
SHA256 hash: 32890fc3efa6d92121da340d64417db068db2dceacfe61f663981adcd596b2e4
MD5 hash: 38457a2dd03a25b561abdbc9824f2c44
MIME type:application/x-dosexec
File name:_queue.pyd
File size:33'784 bytes
SHA256 hash: eb4070d87384565985a59a7139e0903b120044059cb0934a9a425c360e93a34c
MD5 hash: 2ce0e1816468940a4025efb31cd75150
MIME type:application/x-dosexec
File name:_uuid.pyd
File size:27'128 bytes
SHA256 hash: 31c83cb8c5e3eb397252fe871c74fb163d90b88c9e7ac7fd689eeba88c0dd92e
MD5 hash: f7db927202f1fbefaf1260d760eb5ba6
MIME type:application/x-dosexec
File name:_decimal.pyd
File size:259'432 bytes
SHA256 hash: b6edd193dc93d61846be47addd36655aaaf6749ea0409564d04bee6f785ffa15
MD5 hash: 5d54c76a09515d513aab1dd43c401418
MIME type:application/x-dosexec
File name:_elementtree.pyd
File size:134'648 bytes
SHA256 hash: 9b72b42c3fa741025d760db945d47f948271c884e61e5cbfb94f1c99b0446636
MD5 hash: 31db8f46221e06e997c0fa3ecc07d206
MIME type:application/x-dosexec
File name:_hashlib.pyd
File size:67'576 bytes
SHA256 hash: dfacbb48ade3d53780ff1e6875da90930a4a5d593e21984779079bd6f98f3768
MD5 hash: d0a2127b7aa88b6a47c170c933402438
MIME type:application/x-dosexec
File name:libffi-8.dll
File size:39'696 bytes
SHA256 hash: eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
MD5 hash: 0f8e4992ca92baaf54cc0b43aaccce21
MIME type:application/x-dosexec
File name:python3.dll
File size:70'504 bytes
SHA256 hash: e6811bc64d0cc2a8525098b691db364679602c7456894c2f69e1837214a8a705
MD5 hash: 3887abd76341942acef5eaf8999fd3d1
MIME type:application/x-dosexec
File name:_multiprocessing.pyd
File size:37'736 bytes
SHA256 hash: 4616e0b5d2780f30584d031fbef4dea7a1b364aa3dc7a260c0dc02d19cb7cee3
MD5 hash: 32150bed522e6c151fef8027ad4691e0
MIME type:application/x-dosexec
File name:pyexpat.pyd
File size:204'136 bytes
SHA256 hash: 6b4f77625a28693032ae629d8c4bc49a4d05a5362ff8c2d03eaa3dded554bcb0
MD5 hash: b7be486c2c69bd320f05b24a33366874
MIME type:application/x-dosexec
File name:_bz2.pyd
File size:86'888 bytes
SHA256 hash: 0ec5bdf4c688c1d2bda00f61e1f9e1369188c1019173a5412981f6569a997347
MD5 hash: 8bd61ea798d1e3ef58548480ed8ee956
MIME type:application/x-dosexec
File name:vcruntime140.dll
File size:120'400 bytes
SHA256 hash: 36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153
MD5 hash: 862f820c3251e4ca6fc0ac00e4092239
MIME type:application/x-dosexec
File name:libssl-3.dll
File size:792'856 bytes
SHA256 hash: 2e4d35b681a172d3298caf7dc670451be7a8ba27c26446efc67470742497a950
MD5 hash: 4ff168aaa6a1d68e7957175c8513f3a2
MIME type:application/x-dosexec
File name:_overlapped.pyd
File size:58'224 bytes
SHA256 hash: 2c0f17ea5ae1a9f8c1c7d4da1c0cd7d077864174b33bb65a479bdf5e76248d3b
MD5 hash: e9436905d28deaef3b04e1fe2f05d7c3
MIME type:application/x-dosexec
File name:_zoneinfo.pyd
File size:50'544 bytes
SHA256 hash: 835923c7c79cc87decb8a2385ce94027e10b31b1606bae3862afd38e9e370ec7
MD5 hash: 4e0ac6714fd2e66c3e2d3b9cc5b64243
MIME type:application/x-dosexec
File name:python312.dll
File size:6'920'936 bytes
SHA256 hash: b6227a506a9963e7c8182785a54e14a193af51f7b277a61dda04492b499f49ad
MD5 hash: b0939b2f7ec83154e09eabf606179525
MIME type:application/x-dosexec
File name:python.exe
File size:105'832 bytes
SHA256 hash: 805fd29612c221ebea570d372ec5ed46093c25a1033f1765de9b2f8103868886
MD5 hash: ef26d0ae12e1c39269efa78df4107443
MIME type:application/x-dosexec
File name:_ssl.pyd
File size:179'192 bytes
SHA256 hash: 78728b5e06037e3adfe922b59bb1dd19dea391e9ca02e21caab3cdc832111036
MD5 hash: 3eb767de2c65e7f5ece308bfbe4f727c
MIME type:application/x-dosexec
File name:libcrypto-3.dll
File size:5'232'408 bytes
SHA256 hash: 4e5d5d20d6d31e72ab341c81e97b89e514326c4c861b48638243bdf0918cfa43
MD5 hash: 123ad0908c76ccba4789c084f7a6b8d0
MIME type:application/x-dosexec
File name:sqlite3.dll
File size:1'541'992 bytes
SHA256 hash: 8d788b3113a5f168252e0bf13f65c866daba8451c5a4f932141b44fabd85236f
MD5 hash: 46c5df8516637a5f9fe502d5f48a637a
MIME type:application/x-dosexec
File name:select.pyd
File size:33'128 bytes
SHA256 hash: e6bff4f35ab49a84f9e5ccd4b26eff30e1b2d7adb67d91911c4b84bfabcc28b3
MD5 hash: 1fa4cda60c0c11f037b2d6c8cc19afc0
MIME type:application/x-dosexec
File name:winsound.pyd
File size:32'488 bytes
SHA256 hash: 011f1caa7eb8f78cd2918c943e5d406d2f20043f6b7170e1a433ee0cde212b90
MD5 hash: 7aa782e4828ddb3e65867b389f8f53c9
MIME type:application/x-dosexec
File name:_msi.pyd
File size:46'584 bytes
SHA256 hash: 03e0c6d710e884edbc9279d4a8ea1b76e5972c8bf6c2ff0cefb133a3d5459f5c
MD5 hash: 597fc833d1f702b872a827df240c3cde
MIME type:application/x-dosexec
File name:python.cat
File size:571'280 bytes
SHA256 hash: 2d8c2ac1e24c7716c078b17642f6146ac2e92a38a137c06903b3810ee0438760
MD5 hash: 07d62797c8253d025e567dd089a17b19
MIME type:application/octet-stream
File name:unicodedata.pyd
File size:1'139'704 bytes
SHA256 hash: a443f6132d63a683ea3ef463cfe00987e0cf94d02c9e14350795f1a521d05f50
MD5 hash: 25b5e85f911cf5f695f90dac845c1e3e
MIME type:application/x-dosexec
File name:_sqlite3.pyd
File size:127'344 bytes
SHA256 hash: a75cccd75e15e6d9004cda0ed022e86413e1c3f7f02faea3ac990f2f9adc64a4
MD5 hash: d8830605d340b89523cfdfa9094ba7d8
MIME type:application/x-dosexec
File name:_lzma.pyd
File size:160'616 bytes
SHA256 hash: ed997ca4956fe7e27cc702adaa8d31136312361d285b7b845c8829d8c5a89ae8
MD5 hash: 9ec7f84b1976b469c4fa4001d5ff4412
MIME type:application/x-dosexec
File name:python312._pth
File size:80 bytes
SHA256 hash: 2820f241bc9d6810d4db21c21cca3845799367fbdf0199620fb37c86a74b945c
MD5 hash: 535c72e819d6b1e99fc4e85d68784e78
MIME type:text/x-objective-c
File name:python312.zip
File size:3'833'773 bytes
SHA256 hash: 56c5d6ae14659e85cdfbcb0a82298f161060bac9feac2351b52c075bc3125002
MD5 hash: a9b0c501c6db4e96f740c0b33e5ecdca
MIME type:application/zip
File name:2
File size:1'349 bytes
SHA256 hash: 13160d8e413f8a06f47aec8b20edc6ea5d63b63190f77ae9a1ec1bed7195da79
MD5 hash: 7ef51f60309aa7899efdfed89aa1ad6f
MIME type:text/xml
File name:LICENSE.txt
File size:36'874 bytes
SHA256 hash: e502c6b880ff58d614901495a9009c136539cd0b1e2a2abb8fc00b934c203419
MD5 hash: b52c821c7750804295e23b9e94525085
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Clean
File Type:
zip
First seen:
2025-02-05T14:51:00Z UTC
Last seen:
2026-09-09T13:52:00Z UTC
Hits:
~100
Verdict:
Malware
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout T1059.005 Zip Archive
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CAS_Malware_Hunting
Author:Michael Reinprecht
Description:DEMO CAS YARA Rules for sample2.exe
Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Win_FakeInstaller_PythonShellcodeLoader_Crepectl_2026
Author:SixHands
Description:Detects the analyzed fake installer sample using .key config, XOR key, and Python/fiber shellcode loader traits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

c51cb7505cb949897d7d7cd805bef03a

zip 615861fb801e8b04c847598db4e1e46e4b046295017caa37cb5486dde72b5865

(this sample)

  
Dropped by
MD5 c51cb7505cb949897d7d7cd805bef03a

Comments