MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 655c4b5256108b79440e8335bb11dcc181e0534ce988871aabbcbd17dda77c6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 655c4b5256108b79440e8335bb11dcc181e0534ce988871aabbcbd17dda77c6d
SHA3-384 hash: 2410a79dc356522ebddd0ad94b18f3bf79a3d49ff1a2cc983ce90b9da8a71cb4b92f9cbee904640c22b6eb00a9762292
SHA1 hash: edcfe719f7071176f3790f6c667e617b5c21b076
MD5 hash: 0896017210e0c48c458786eedf39ea4d
humanhash: mountain-football-mango-summer
File name:extension-fix-GYIUDM.hta
Download: download sample
File size:3'031 bytes
First seen:2026-07-31 13:20:14 UTC
Last seen:2026-08-03 08:42:27 UTC
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 48:/f3ZjwquGSTO7jj4FjpWtfVnQrsvoSSzfvB01aQ5vjNM:5jwqWC7jMpWtJQgvoSS7vS1akpM
TLSH T1B7513CF7B94252C9BD314A9B1A2F608D54D86A432366D1F8F292EC00EF8DF5944787D4
Magika html
Reporter abuse_ch
Tags:hta

Intelligence


File Origin
# of uploads :
2
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
File Type:
hta
First seen:
2026-07-31T11:13:00Z UTC
Last seen:
2026-08-01T22:24:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus detection for URL or domain
Clears Internet Explorer cache and cookies (likely to cover tracks)
Suricata IDS alerts for network traffic
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1950639 Sample: extension-fix-GYIUDM.hta Startdate: 31/07/2026 Architecture: WINDOWS Score: 60 25 atualizaonavegador.com 2->25 29 Suricata IDS alerts for network traffic 2->29 31 Antivirus detection for URL or domain 2->31 8 mshta.exe 2 55 2->8         started        signatures3 process4 dnsIp5 27 atualizaonavegador.com 104.21.10.187, 443, 49769, 49770 CLOUDFLARENET-CloudflareIncUS Canada 8->27 33 Clears Internet Explorer cache and cookies (likely to cover tracks) 8->33 12 rundll32.exe 1 58 8->12         started        15 rundll32.exe 8->15         started        17 rundll32.exe 8->17         started        signatures6 process7 signatures8 35 Clears Internet Explorer cache and cookies (likely to cover tracks) 12->35 19 rundll32.exe 9 58 12->19         started        21 rundll32.exe 15->21         started        23 rundll32.exe 17->23         started        process9
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Html
Threat name:
Document-HTML.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-31 13:07:06 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MalScript_Tricks
Author:@bartblaze
Description:Identifies tricks often seen in malicious scripts such as moving the window off-screen or resizing it to zero.
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HTML Application (hta) hta 655c4b5256108b79440e8335bb11dcc181e0534ce988871aabbcbd17dda77c6d

(this sample)

  
Delivery method
Distributed via web download

Comments