🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b50fa3187c3b8d3efd4fa2a9a0df6e98800a4613b439d3493ee24dc28e4e440. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 9 File information Comments

SHA256 hash: 8b50fa3187c3b8d3efd4fa2a9a0df6e98800a4613b439d3493ee24dc28e4e440
SHA3-384 hash: 7d3036635c6ad1a9b93b10a8f252d94b5012b23c8559fafc927a0f5da319330624a2dd902dee654c8900834c32b9990a
SHA1 hash: 8a7e2bed07f8d9d9c08b5feef4921668c17a9747
MD5 hash: d161a777bcd49abf645edb9eb409760e
humanhash: enemy-india-nineteen-victor
File name:8b50fa3187c3b8d3efd4fa2a9a0df6e98800a4613b439d3493ee24dc28e4e440.bin
Download: download sample
File size:228'972 bytes
First seen:2026-10-02 12:18:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:jL0oZxmZ/3YBEQzFJ0T/zfQ3DiL13RGP64WIzpRnjHSN3P:jLFWWBE9ou1BGPXZrnjWP
TLSH T12424236668ABBD7DF56588FED57463CCCB21C0109B107E039A2008CB51A6E9D73EB1E7
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
US US
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:NetDefteri.exe
File size:391'168 bytes
SHA256 hash: ecdf61116145eb301d1ad6e4a62d7316653949b1f49f4636d9ee7b3b8d9d1160
MD5 hash: 8e265729b81027e30fba9393f95f05b4
MIME type:application/x-dosexec
File name:NetDefteri.exe.config
File size:157 bytes
SHA256 hash: 4f66ae8ab644a65e344e0fa4ce900190837bd6f8a864acf2db49496712202944
MD5 hash: eac147884825358c926971dcf2224c52
MIME type:text/xml
File name:ocr.ps1
File size:3'034 bytes
SHA256 hash: 0026a826fe9aa4704fafb151a395d2aa1de75635f9d60d9f45eb8a822a0ec3e1
MD5 hash: bb3ad7bf9ca3315da2fbd6bd752e28dc
MIME type:text/plain
File name:KULLANIM.md
File size:2'715 bytes
SHA256 hash: c49a716a3c0008cbd14b3fdb318b061491cc68026697ea98072988346cc95fc4
MD5 hash: 8d4b073f3c86d8f59e47ba156223beb6
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
ai-born base64 llm-interaction packed reconnaissance
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.18 T1059.001 Zip Archive
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-02 12:19:37 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
3 of 23 (13.04%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: PowerShell
Enumerates connected drives
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:HUNT_NET_Loader_ImagePixel_To_AssemblyLoad
Author:Anish Bogati
Description:Hunting: .NET loader that reads pixel data from an embedded image, loads it as a .NET assembly, and runs it via reflection or late binding. Catches bitmap-steganography loaders.
Rule name:LLM_API_OpenAI
Author:llm-api-abuse-pilot
Description:References OpenAI API endpoints or key material
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 8b50fa3187c3b8d3efd4fa2a9a0df6e98800a4613b439d3493ee24dc28e4e440

(this sample)

  
Delivery method
Distributed via web download

Comments