MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b58e9774417890cc6e76d1fee77292d990bba0ceab88abd6d5929b66c44c9cce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b58e9774417890cc6e76d1fee77292d990bba0ceab88abd6d5929b66c44c9cce
SHA3-384 hash: 72b79540ab813f41c8b3eaa32f59667da1617cac79d45bcbcab6a3e137442ca693d9b8d5407eb834c33cebaf64894ffe
SHA1 hash: 16571ca9fcc791dc0116aa8faffac6ce9b9b411d
MD5 hash: 7a8988640beb7cad7818b8ed254169de
humanhash: rugby-utah-bulldog-hydrogen
File name:setupMP.7z
Download: download sample
File size:1'473'260 bytes
First seen:2025-12-01 08:34:15 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 24576:32d9GUqsdu4kk0SpX2e/6BOxGFQv09cOVUmIj6uGKtJiIv+uUy0lWc5+M4YBHMOj:A9GUvjkktXv/6wECv0jijoKmpu50lWmr
TLSH T1E56533F568329171CF24C865EE8F10190DE2291F0F46AFB139BD42D5601A79FD8AD8BD
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter juroots
Tags:7z

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
96.5%
Tags:
trojware virus delf
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
borland_delphi installer-heuristic overlay packed packed packed upx zero
Result
Gathering data
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive Executable PE (Portable Executable) PE File Layout SFX 7z
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

7z b58e9774417890cc6e76d1fee77292d990bba0ceab88abd6d5929b66c44c9cce

(this sample)

  
Delivery method
Distributed via web download

Comments