MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a330d9a9f623566f6b5a4610e77a52edb144ff4d534e7f0b4c8d523ab2cfffcb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 7 File information Comments

SHA256 hash: a330d9a9f623566f6b5a4610e77a52edb144ff4d534e7f0b4c8d523ab2cfffcb
SHA3-384 hash: ea7ee16cd37d6d6e0e4bcbd496fd04956c21258cfb78257152aad429b77e19932dc682fe1b436d2d49613aad105546a4
SHA1 hash: a4af21cb99f492b420c13fe678d43413b0a75b5c
MD5 hash: 571b08c42ee40cb7dfb4765c31db85e8
humanhash: avocado-finch-cup-timing
File name:0VldcRGDA076852FKZEXR_83K0.iso
Download: download sample
File size:5'902'336 bytes
First seen:2026-04-14 14:44:00 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:vD7+dqvcfsT5/iG0yxHnNX9hc8fih1qGdxeI+TR4dxyiNdznzg5jGegFuim3YUsl:4uim3YUspr
TLSH T1595623326F456C63C99047B5B10F6F217E7D8747860CD5E6A19CA0863B8FF90892F4EA
TrID 87.8% (.NULL) null bytes (2048000/1)
10.9% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.5% (.WAR) Warcraft game data archive (12007/4/6)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.2% (.CPT) Mac Compact Pro archive (5000/1/2)
Magika iso
Reporter cypherpunk472
Tags:iso trojan.zbot VBS/Agent.CNT zbot


Avatar
cypherpunk472
https://vmi3231296.contaboserver.net/?_task=mail&_action=get&_mbox=INBOX&_uid=49338&_token=8a2e476db7f0f1c0cda1170cd683901d4e85279c432a2552191ae26bfeca16c9&_part=3.8.6&_embed=1&_mimeclass=image

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
CO CO
File Archive Information

This file archive contains 14 file(s), sorted by their relevance:

File name:lnmdg2.xml
File size:15'744 bytes
SHA256 hash: f48925e9eb4191414ac50b742277ab244418591a89550cb314c0130c09b21af3
MD5 hash: 9d61f386ad24c251ff032a89969fe28d
MIME type:application/x-dosexec
File name:qvilzd1.xml
File size:81'176 bytes
SHA256 hash: 20186a2657ee3c17e5b7ee5654ac73b7d34b5d480380f7c80e02955ef3d772a8
MD5 hash: 0ddb14f218c5dbff6daab48a38bd95ec
MIME type:application/x-dosexec
File name:gbmi4.pdf
File size:25'980 bytes
SHA256 hash: a71b2b1a3dddbc7cac66792e66d364525410887d53a2e459d2c8548b1c4b59cf
MD5 hash: c02d8fe60889d077091f6088d0c42bb7
MIME type:application/pdf
File name:taegv8.pdf
File size:1'891 bytes
SHA256 hash: b7744303249a322c3bdf94c5b16057d156c2a1cadd0ada563c39c325d35603b2
MD5 hash: c3e51622b819d2ae3e850212bfa8c33d
MIME type:application/pdf
File name:0ValidaJ05B35187070utcqKJQHA_GBF19H528670-NOPSQC.vbs
File size:5'189'754 bytes
SHA256 hash: a41e2d67c4abad65f15e2645844c5b313708e2139e1a996dd62533f03603058a
MD5 hash: c06eef1762bd6b72f073f9ab7dac6cde
MIME type:text/plain
File name:hxee6.pdf
File size:1'741 bytes
SHA256 hash: c7fe3d568803ff8f343bb1078999f961a6e96fc1726c016b73595fcd1bddd789
MD5 hash: a25c9b8ff5077402ad25523130a96de1
MIME type:text/html
File name:shubp2.pdf
File size:27'497 bytes
SHA256 hash: 8ac50f41fba3f8d930950f8e54bbd1ca094b460831e8a6ff7be555834a77afc4
MD5 hash: 3c086d7a43532065c323662742b6e3dd
MIME type:application/pdf
File name:zlmb1.pdf
File size:26'274 bytes
SHA256 hash: d16e612684acdb0139b14395d8a2063f3fb3cf72289e0b18c9874391c00d741e
MD5 hash: c2c20eac60f8479ce8eb4139455229b8
MIME type:application/pdf
File name:mkareo7.pdf
File size:12'546 bytes
SHA256 hash: 0e65316295a1d7edc7ff02ee398cb972e7e59b3c3ec6b319313683aeee889cdd
MD5 hash: 4c079a927ddd3f869ce13c1c3ac82390
MIME type:application/pdf
File name:xhfp9.pdf
File size:25'875 bytes
SHA256 hash: 385e38aac8b96bb9ca2e6ed3c6b813df0c9f07dae6f7e6b63ca2a4638e133ed9
MD5 hash: 7ba4be92f6345e55f4546e15b4148684
MIME type:application/pdf
File name:srpo3.pdf
File size:40'944 bytes
SHA256 hash: 00aad6746650ee7e8a749d7adb55c883fd3dcb49846e08a53388d28d2b167c6c
MD5 hash: 9512e45453b46b46c3d5149563dacf06
MIME type:application/pdf
File name:sqahpa5.pdf
File size:25'715 bytes
SHA256 hash: 91258cc25e35feb951a9b3e6f99f4b082c6220a2fff982e0a45bc5c17f4932b5
MD5 hash: ae228fcc1253d7b6f62b0d25f4a8cd8c
MIME type:application/pdf
File name:2
File size:346 bytes
SHA256 hash: 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e
MD5 hash: 24d3b502e1846356b0263f945ddd5529
MIME type:text/plain
File name:epco10.pdf
File size:25'029 bytes
SHA256 hash: 134ae5f08ee3bc450bd8aa6d7a3bfdafeec4a341fcc81e83d6430eacb71acc0a
MD5 hash: e8ee5f06c3164494aed226750e2a4ce8
MIME type:application/pdf
Vendor Threat Intelligence
Malware configuration found for:
Archives
Details
Archives
extracted archive contents
Verdict:
Malicious
Score:
90.2%
Tags:
vmdetect zbot
Verdict:
Malicious
File Type:
iso
First seen:
2026-04-14T11:50:00Z UTC
Last seen:
2026-04-14T12:03:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.VBS.SAgent.gen HEUR:Trojan.Script.Generic HEUR:Trojan-Downloader.Script.Generic
Gathering data
Threat name:
Win32.Infostealer.Zeus
Status:
Malicious
First seen:
2026-04-14 14:38:51 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
7 of 37 (18.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware discovery link pdf qr spyware
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via e-mail link

Comments