MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0427a2cdd11cbbc5a5e79d5fe3c79a5922540bd75350edee8423facea489783. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: a0427a2cdd11cbbc5a5e79d5fe3c79a5922540bd75350edee8423facea489783
SHA3-384 hash: a6aa021734368a1d2c9cdab40b3edfe54d3f76ba10f08e1718e383b01c0d7fa3952226550c144195cbc47db17457282b
SHA1 hash: f06168fe8808567e1c3a2986bcf355160268024d
MD5 hash: 44208c037d62fa9a0528450b6fbed316
humanhash: avocado-queen-ten-mobile
File name:Windows_Update_Assistant (3).exe
Download: download sample
File size:90'262'056 bytes
First seen:2026-07-26 11:36:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (589 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:vge4hdV6xfMCginFt90c3Hkc7M0zLr1X3OznfxySo3RPqSlfVDWTzS:vge4DoxfMCFnF7z3V7vl385ySor0TzS
TLSH T166183321855206BECE55AF3490F1A33641BFBF76AF30A13F09A6B58DAD33A4B5470C16
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 8c32f0cccce86996 (1 x Sazoora)
Reporter JAMESWT_WT
Tags:exe Windows-Update-Assistant

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Searching for the window
Searching for the Windows task manager window
Launching a service
Creating a file
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Changing a file
Deleting a recently created file
Running batch commands
Creating a process with a hidden window
Launching a process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context adaptive-context anti-debug crypto installer installer microsoft_visual_cc nsis packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-18T23:04:00Z UTC
Last seen:
2026-07-18T23:21:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-07-18 17:39:01 UTC
File Type:
PE (Exe)
Extracted files:
3563
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Command and Scripting Interpreter: PowerShell
Drops file in System32 directory
Enumerates processes with tasklist
Checks installed software on the system
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Modifies Windows Firewall
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments