MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a357c7ee9edeccfd1cefab17aeef18aaa2dd3b44d1779728e9276518f4a9b547. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a357c7ee9edeccfd1cefab17aeef18aaa2dd3b44d1779728e9276518f4a9b547
SHA3-384 hash: c1d249bc597a1cf640a9cf401c8e2f14519ae88d0015d821ed57cb9bcba967de362feebcec0495e7081ecc2a19ab3cc9
SHA1 hash: 24d55f106d4392b601a260aa8b46c51cd7f6e818
MD5 hash: 7aa50f7584b6eec21fd33a59015f154b
humanhash: paris-romeo-bluebird-burger
File name:taxhuman.hta
Download: download sample
File size:2'008'219 bytes
First seen:2025-01-30 05:58:01 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:application/octet-stream
ssdeep 12288:fByKrKvv3K4vavmKyKmv1vrvuKYKNvqKjvUv6vBv2KX9fBFvIKB8TvDK+:fxOq1HyJFfNZPCi+
TLSH T15D951D0E5769B61ED5204234B8CD432B3375EC8C4A8B974B5589B0306CB62E9EED46FF
Magika zip
Reporter JAMESWT_WT
Tags:89-23-102-187 booking hta

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
dropper delphi shell smtp
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Result
Verdict:
UNKNOWN
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery execution
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HTML Application (hta) hta a357c7ee9edeccfd1cefab17aeef18aaa2dd3b44d1779728e9276518f4a9b547

(this sample)

  
Delivery method
Distributed via web download

Comments