🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afcc9ef22dce6325cbb04fcc582018814025af6889e2bfc0278f28d176155c91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 8 File information Comments

SHA256 hash: afcc9ef22dce6325cbb04fcc582018814025af6889e2bfc0278f28d176155c91
SHA3-384 hash: 19ddedd3dc01c3dc6c70fb04022965bd1a94bcda13b837a474d3450195207ee0aede8ed79d89816cccb6349d253fba55
SHA1 hash: a906909c290c2ae0c50ea1d6f409c5c2f2a5bbfe
MD5 hash: 74f0c9929b0adefb0416de52f7221f44
humanhash: oxygen-bluebird-queen-zulu
File name:Check and verify billing details.vhdx
Download: download sample
File size:71'303'168 bytes
First seen:2026-09-24 16:19:02 UTC
Last seen:Never
File type:
MIME type:application/octet-stream
ssdeep 196608:Dt5NXIyWYz0PUr1o77nO9/jPbMGgJvu4O7NADtV6v+v:R4y3p8O9rPQGT7
TLSH T168F7C0127E480C27E45A3330CF4DA2F8A77E9DE237529AC769A0BD4DBA316411E76317
Magika iso
Reporter smica83
Tags:vhdx

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
HU HU
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:CERT-In2035112409.EXE
File size:1'165'640 bytes
SHA256 hash: 667676b34d9f782d86e0ea0e719833567b0707b810c03d9deb6964a9f67a7d17
MD5 hash: 25b3279e30838b2beae8e1076a423e06
MIME type:application/x-dosexec
File name:6270ed28-a41c-4bbc-b784-d715a1de7143.mui
File size:18'120 bytes
SHA256 hash: d599d6659b713b8dd0febbbec15094e366d34cfce35940e4ff2547306c4073a4
MD5 hash: a51ae310b84cf4e7bab23893d72501bc
MIME type:application/octet-stream
File name:ttdloader.dll
File size:14'960 bytes
SHA256 hash: 9c66615488235f1b3c7bc21bd2ace4e9f79866d955e9932e4da039f313204d2d
MD5 hash: 1b7bc31b86b4be14e4049cd573264a82
MIME type:application/x-dosexec
File name:pdfcore8.DLL
File size:8'404'992 bytes
SHA256 hash: 7ec6f33319e929be8a52015652335dd4061344e14514c05cd4e209e7d6bead77
MD5 hash: c5de81431642a413fc3c59526f804a77
MIME type:application/x-dosexec
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
discimage.vhdx
First seen:
2026-09-24T15:48:00Z UTC
Last seen:
2026-09-24T16:12:00Z UTC
Hits:
~10
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments