🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab5f742586899581352c7ebfb5db7f40d2b53bb817802e78e0938bcfdd72baf7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: ab5f742586899581352c7ebfb5db7f40d2b53bb817802e78e0938bcfdd72baf7
SHA3-384 hash: 0c95d3d5d3fd872e03c47c3660567e2f8a75315f8af7d9bb788e73326984c4ddd5512b84e1deb0b04741fa6eeb8ed65b
SHA1 hash: bf90aff64ff48ea575b9dacb0327c0da7582d64f
MD5 hash: f6d9733675e87b0aafbb0a9d8f66283b
humanhash: sad-michigan-charlie-stream
File name:Adobe_Reader.zip
Download: download sample
File size:13'054 bytes
First seen:2026-09-11 12:29:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:mfu7UFYjCTWcKhRjEcaTalg0/ixh7UPIj+gFq48o:msKTM3UGlJixGQCgFn
TLSH T1F842B07AD86EECAB444C68DA6C46EA333341353B0FBE49605F6A542E107BC91399C1D7
Magika zip
Reporter cocaman
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Adobe.Reader.js
File size:46'282 bytes
SHA256 hash: 1d25cf1b14e918c0d6922d30f3b5766424c64a2965c220ab89d909e10aace891
MD5 hash: 9028ab5e30758a26c9639dc0566b0ddf
MIME type:text/plain
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cscript evasive expand lolbin lolbin obfuscated powershell repaired rundll32
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-11T11:59:00Z UTC
Last seen:
2026-09-11T12:07:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-11 12:30:45 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
backdoor defense_evasion discovery execution persistence privilege_escalation rat revoked_codesign
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Hide Artifacts: Ignore Process Interrupts
Boot or Logon Autostart Execution: Authentication Package
Drops file in System32 directory
Enumerates connected drives
Checks computer location settings
ConnectWise ScreenConnect remote access tool
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Sets service image path in registry
Signed with revoked ConnectWise certificate
Malware Config
Dropper Extraction:
https://pub-814de71aba7d4258ae0ca369fdb8002f.r2.dev/WindowsExplorerSupport.msi
https://github.com/chockscity/x9q3m2k7b/releases/download/v1/a.msi
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments