🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a3229cd4a78c6cd01f4be351de1969eb159217381b32616244bdad800f4d2a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NWHStealer


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 8a3229cd4a78c6cd01f4be351de1969eb159217381b32616244bdad800f4d2a6
SHA3-384 hash: 847f3b50f0e443911f6d27c84bb0f24b16ad072333fb39905156782980cf139aba349013914ca5cddf9faeceee1f40b2
SHA1 hash: dd04fe5ef69d9e04294b757d705fcf4f5005e5cf
MD5 hash: f56b94e6834152bebb1e49ab8a0425d9
humanhash: ink-mike-red-victor
File name:JSON.Mod.Manager.v10.5.zip
Download: download sample
Signature NWHStealer
File size:42'748'996 bytes
First seen:2026-05-30 11:42:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 786432:oFKw3qhTN8nTTO/KDps4zkDupZ4IJjBWzNod+LC28a7cqueYYQsDjsQ:oH9HO/Eps4zkDucCW0SC22peYYQeoQ
TLSH T10B9733C87CF02487FC329942446B5ACEE131E426687A49FF665A472CB6C0FD457FA19C
Magika zip
Reporter burger
Tags:NWHStealer zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
DE DE
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:JSON Mod Manager v10.5 .exe
File size:117'440'512 bytes
SHA256 hash: cc6b71e9ad9098c329427da3006bc00626bf79b1b4c0523373bda7ad20eb71bf
MD5 hash: 4a4712f1ada2500a9a121daaf189df0b
MIME type:application/x-dosexec
Signature NWHStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscate shell sage
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto fingerprint obfuscated overlay packed reconnaissance rust
Verdict:
Clean
File Type:
zip
First seen:
2026-05-30T12:57:00Z UTC
Last seen:
2026-05-30T13:55:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win64.Malware.Generic
Status:
Suspicious
First seen:
2026-05-30 11:44:50 UTC
File Type:
Binary (Archive)
Extracted files:
17
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

NWHStealer

zip 8a3229cd4a78c6cd01f4be351de1969eb159217381b32616244bdad800f4d2a6

(this sample)

  
Delivery method
Distributed via web download

Comments