MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64286266f8d011f6a7cd3cc1d091c9b2ff5305a49374fc079d8914f97a3c9558. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: 64286266f8d011f6a7cd3cc1d091c9b2ff5305a49374fc079d8914f97a3c9558
SHA3-384 hash: 12286378346a4552913e5302bd94c4259d0c63d2d045887bed34c8b4ecdac7b6df9e0c89fff3d2badeccd1fe6b57a5fe
SHA1 hash: f1d3a2feb22fdfe9e37527e49ae26e839cce2a90
MD5 hash: ae0450890ffa706e8bb4946d900a1b17
humanhash: may-pasta-bakerloo-king
File name:837a3d2da109d9889fd481898f042f5d67664b83185d15a01a6f95799c8d3644.7z
Download: download sample
File size:758'204 bytes
First seen:2026-04-13 18:42:46 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 12288:YgHncIjPmgHl4SayQf/hE547kwxJJ5hIfBRyPK3MKsiKJ6qUn4Dpz9gh4uy2021t:Yu1jO6uty4E5APH5hIfBR4BiKJDUn4mX
TLSH T15EF423FB065AB0637777033A94491ACB88D311D4BB64AF914E6A014E37737F7690B0A9
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter johnk3r
Tags:7z svg vault88x-secure-efficient2-su

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:837a3d2da109d9889fd481898f042f5d67664b83185d15a01a6f95799c8d3644.svg
File size:1'039'684 bytes
SHA256 hash: 837a3d2da109d9889fd481898f042f5d67664b83185d15a01a6f95799c8d3644
MD5 hash: b620054a818ef1ecf29febf15f3ce6bf
MIME type:image/svg+xml
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
infosteal autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
encrypted obfuscated textdecoder.decode zero-day
Verdict:
Malicious
File Type:
7z
First seen:
2026-04-14T18:30:00Z UTC
Last seen:
2026-04-14T18:44:00Z UTC
Hits:
~10
Gathering data
Threat name:
Document-HTML.Packed.Generic
Status:
Suspicious
First seen:
2026-04-13 18:43:37 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
4 of 23 (17.39%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:svg_attached_js_code
Author:Anish Bogati
Description:Detects suspicious SVG files with JS code and base 64 encoding
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments