MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 932acab2f2f20534a2eecac47f99acfbebd0383db6f920280713d54dec503fa2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 932acab2f2f20534a2eecac47f99acfbebd0383db6f920280713d54dec503fa2
SHA3-384 hash: 4b4379031880057e15e3877e2f9cfdf6f5eeeafebb824a0bc453b01d363ae3f5540ec7086b8ed6a7b98925c0b0199690
SHA1 hash: 9c6790e643c007c82dd6597f3a707ae7ddbd25cb
MD5 hash: ca28f96839c5f043493821a95bfee6f3
humanhash: virginia-whiskey-lima-pasta
File name:932acab2f2f20534a2eecac47f99acfbebd0383db6f920280713d54dec503fa2
Download: download sample
File size:17'158'144 bytes
First seen:2026-06-15 10:13:00 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 393216:ipF1+43wwXHdYNdZZuUXjyQzxDWOkmOLvRIC8XzFYe3vmBmLLh:i313zYN/djXhkmOL+5zFYY7Lh
TLSH T1FB073305B840AB1BD1FA783CF98ED4A9BA04FC952A1A540B3D25F0DCDDF25B171F6892
TrID 86.8% (.MSI) Microsoft Windows Installer (454500/1/170)
11.6% (.MST) Windows SDK Setup Transform script (61000/1/5)
1.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter JAMESWT_WT
Tags:centrogauchodabahia123-com msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
shellcode dropper autoit virus
Verdict:
Malicious
File Type:
msi
First seen:
2025-11-01T10:53:00Z UTC
Last seen:
2025-11-01T11:09:00Z UTC
Hits:
~10
Detections:
UDS:DangerousObject.Multi.Generic Trojan.Win32.Zapchast.botf Trojan-Dropper.OLE2.Agent.sb HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Win32.Trojan.AutoitInject
Status:
Malicious
First seen:
2025-10-30 22:29:42 UTC
File Type:
Binary (Archive)
Extracted files:
39
AV detection:
20 of 36 (55.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery persistence privilege_escalation ransomware
Behaviour
Checks SCSI registry key(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments