🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 7


Intelligence 7 IOCs YARA 6 File information Comments

SHA256 hash: b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636
SHA3-384 hash: ecc1da556f5379856bb8b339001d942eabfd2ca15f3d3d7bee9e0e5bc90c7030474b992959e5af101baba15ab362fd13
SHA1 hash: ddee4ee51bf954bafd69256fa47f0a8e2ea2551c
MD5 hash: 4100b976150cb4015e1856d875637861
humanhash: north-freddie-vermont-arkansas
File name:b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636.bin
Download: download sample
Signature ConnectWise
File size:6'748'465 bytes
First seen:2026-09-13 08:01:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:zsLD6bmXv8UNTQxAHyksE4YHt2N0G0fJJPF:QCbmEhANsEpNOP2JJPF
TLSH T10B66337FDFEAB6C2D937DB75842A1589AFF4C7AB32D47092242C449279CD1A2D8E0301
Magika zip
Reporter whack_sh
Tags:ConnectWise zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
US US
File Archive Information

This file archive contains 14 file(s), sorted by their relevance:

File name:config.php
File size:576 bytes
SHA256 hash: 439ca7ad007c52cfda3ceb67432d388575affd1d62bdd842d6e71d5e55f9e10e
MD5 hash: 2a864a99ed809b9092f0dfc11bb6305e
MIME type:text/x-php
Signature ConnectWise
File name:Justamoment....php
File size:11'846 bytes
SHA256 hash: 2aab56dc1ac0fd84074bda8b9a7fee694cd76e3dd91d13e036951db363e10e0b
MD5 hash: 25c5c92f84dcaf5c483f954965e35e20
MIME type:text/html
Signature ConnectWise
File name:docusign.dmg
File size:5'829'950 bytes
SHA256 hash: 128fdd44526c4e3102421425c23e3c5a5bf49f38eb13a98eea8b08817df2a47e
MD5 hash: 7b7733a794dcc45e8d146e1f6439b588
MIME type:application/zlib
Signature ConnectWise
File name:doc.png
File size:520'475 bytes
SHA256 hash: 1d0d483650acb876bfa78882927242ef75c246d9a83a6456a6c3f2dd00b575aa
MD5 hash: 6bb7b475f9838045a9d64cc5a7018af9
MIME type:image/png
Signature ConnectWise
File name:index.php
File size:61 bytes
SHA256 hash: c13eb6c920095e5b56fbde380e4a87d032b0b33bc839efecb53a870b75a4b1f0
MD5 hash: 4041b076305e8fb37781c003d1c41abd
MIME type:text/x-php
Signature ConnectWise
File name:invite.php
File size:843 bytes
SHA256 hash: ac6283c91a1cdd50448099b23df68e3d4f2d4d7dc0b0cf1adea1068a4c0b641c
MD5 hash: c8a3d971910597ae5bd658bc808c8d80
MIME type:text/x-php
Signature ConnectWise
File name:visit.php
File size:1'268 bytes
SHA256 hash: ccc0b8270b1e08ef7055e90e85c52da6657fda4ca9b9ae684e8d8de0fa0b96df
MD5 hash: f9d37eb414a1c093a4778b88dccc3691
MIME type:text/x-php
Signature ConnectWise
File name:Device-error.php
File size:4'784 bytes
SHA256 hash: b360638546fc327ca2213bb62dff67427387020b9199020f27713e00e442902c
MD5 hash: 398016d77f56bbef8d343267a0fea3a6
MIME type:text/html
Signature ConnectWise
File name:doc.php
File size:897 bytes
SHA256 hash: 10f7ad3f9686f8148fadb9fc8f3fa5b638c9a1fb26005246da2e1f5da00a58ea
MD5 hash: 38d7484123e75bc144b317b1afbd50b9
MIME type:text/html
Signature ConnectWise
File name:utility.php
File size:302'727 bytes
SHA256 hash: e9e6a6a564cf56c00a63b49feba06b479fa7538672afb503c6c3041677c4ba39
MD5 hash: a4fad45bae1a2d71b2b81847cd09f90e
MIME type:text/html
Signature ConnectWise
File name:blocker.php
File size:4'984 bytes
SHA256 hash: 638605a5a9ff9e0eb77c64e9da4c920d4c2e82cc8728577d5203d50fed4c9235
MD5 hash: 82b58d9b5e35cc6f26eb40494bb42523
MIME type:text/x-php
Signature ConnectWise
File name:v8c78df7c7c0f484497ecbca7046644da1771523124516
File size:31'169 bytes
SHA256 hash: 4b77eae349a8cbcea7133cf3640a64ebf1f69d54d8f6469d7be6fdc188ca4ca4
MD5 hash: 4f67ea9205c3ca7c9e04582d3b9bdd1d
MIME type:text/plain
Signature ConnectWise
File name:settings.php
File size:273 bytes
SHA256 hash: 3e0a154eea5155a2ee934e08a923cb1565d340850726dcce1f7ecbf4ff437ede
MD5 hash: 116a64393af0f3b0c8fb744f2c4aee96
MIME type:text/x-php
Signature ConnectWise
File name:Docusign-Installer.vbs
File size:2'458 bytes
SHA256 hash: d3d877e529792a6e07756c840fd62598599f096ae7d4c296f5f5025b4501050d
MD5 hash: 871d6eab90f50428b74f6e289dfb4925
MIME type:text/plain
Signature ConnectWise
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-02T08:50:00Z UTC
Last seen:
2026-09-03T03:45:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
2 match(es)
Tags:
ADODB.Stream COM Behavior Trace DeObfuscated MSXML2.ServerXMLHTTP Obfuscated SOS: 0.19 SOS: 0.36 SVG T1027 T1059 T1059.005 T1105 VBScript WScript.Shell Zip Archive
Threat name:
Win32.PUA.ScreenConnect
Status:
Malicious
First seen:
2026-09-03 06:12:00 UTC
File Type:
Binary (Archive)
Extracted files:
90
AV detection:
16 of 36 (44.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
backdoor discovery execution macos persistence privilege_escalation ransomware rat revoked_codesign
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:flashakacoder_kit
Author:Lenny-3BO
Description:FLASHAKACODER PHP banking kit -- operator tag + admin chain + Telegram exfil + HTML form-action
Reference:hunts/flashakacoder-tarrarat-cluster
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectWise

zip b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636

(this sample)

  
Delivery method
Distributed via web download

Comments