MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8dd6345a1b878d0f9c0d852a5bb381d7b5df30861a9d3027825668d32fd1bfcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 8dd6345a1b878d0f9c0d852a5bb381d7b5df30861a9d3027825668d32fd1bfcf
SHA3-384 hash: e61e9cb0c54cce1a7f73ba9a75cfb31df0d063b5194ec1462fc2f9fb83571d7b56d44e9a778ca13b326b28f8cb8166c0
SHA1 hash: 346313914d876446178d3254ed77c406e9b9f150
MD5 hash: ccdef6d7163c9c5cf3893dd20e4422ff
humanhash: comet-magnesium-four-triple
File name:swift_copy.zip
Download: download sample
File size:110'590 bytes
First seen:2026-07-24 12:45:13 UTC
Last seen:2026-07-24 12:46:41 UTC
File type: zip
MIME type:application/zip
ssdeep 1536:A4CgM2Cmk+2HNYhvSqo6H5nbJe+ZzHyY/yZeznpou+5bOtR6mZrFSkyWr4RuWoJu:A/FEgyvJHNJe8zSYqZomOtRp+k0ErNgr
TLSH T118B31281B59D8D020B73C6A4E5934C443AF5772A21CCF2946FBE973A14AF76DC0E4876
Magika zip
Reporter TomU
Tags:zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
74
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:swift copy.js
File size:302'020 bytes
SHA256 hash: 512547dbc95da7132813f4d2d624779410a862356601ed56e5f677be5bc7c3dc
MD5 hash: e29029ca669f6890b76bfd3225e60087
MIME type:text/plain
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive obfuscated repaired
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-21T05:19:00Z UTC
Last seen:
2026-07-23T03:10:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Script-JS.Trojan.Divergent
Status:
Malicious
First seen:
2026-07-21 17:39:44 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip 8dd6345a1b878d0f9c0d852a5bb381d7b5df30861a9d3027825668d32fd1bfcf

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments