MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7ab674c5ce421d9233577806343fc95602ba5385aa4624b42ebd3af6e97d3e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b7ab674c5ce421d9233577806343fc95602ba5385aa4624b42ebd3af6e97d3e5
SHA3-384 hash: 047e2b464a83bbf778db23e38942f325355cea9eee39fe2a4f2ba44acf0bf86dc4a3e519d4da021fb92677884f025e10
SHA1 hash: 884c7f88f367b956183dc6cf78f620bd9e4d4296
MD5 hash: e4def2aa4d18d3e6ad6922446f68366c
humanhash: lemon-oscar-alabama-bravo
File name:util.py
Download: download sample
File size:1'361 bytes
First seen:2025-08-08 12:57:56 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 24:1olLUpXHdYMyIrLWktfTlKRbwC8XA1s7OSBwAceoWiiPgCwjgv8:1o8XHaMXrLW+TsRb38Q1sd4iy
TLSH T17821FB10CC09006046B31B0E4E81DAE6E34847C74F172142FB5C9B206F789B8CA69AAF
Magika python
Reporter JAMESWT_WT
Tags:py PyLangGhost

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
IT IT
Vendor Threat Intelligence
Threat name:
Script-Python.Trojan.Pylangghostrat
Status:
Suspicious
First seen:
2025-05-13 16:35:28 UTC
File Type:
Text (Python)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments