MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ba98397db3a64b70825a4decf232fb000f3ba3ef4baae8c0519ded6f2153820b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 9
| SHA256 hash: | ba98397db3a64b70825a4decf232fb000f3ba3ef4baae8c0519ded6f2153820b |
|---|---|
| SHA3-384 hash: | c83affb25533605308f720eb0216aa72ad984af4bcb575d023647438c79d713d09dbfcc3d8fb9008c20d66f8722af8c5 |
| SHA1 hash: | 556c81d57671b2e473adf7b4f6f82bf3f2a7fbb1 |
| MD5 hash: | bc24fbc8fc7ca5d1264f133a69e42bb2 |
| humanhash: | fix-fanta-pluto-quebec |
| File name: | Pemberitahuan Penyesuaian Gaji.7z |
| Download: | download sample |
| File size: | 595'752 bytes |
| First seen: | 2026-03-03 09:44:30 UTC |
| Last seen: | Never |
| File type: | 7z |
| MIME type: | application/x-7z-compressed |
| ssdeep | 12288:qbMyAaIew2A1XaCriCnErgX07vKV9CUPGAcSGqdJjacgWfIdmO/QD:uMVOKZ+FrjiV9CN6/dJjwLi |
| TLSH | T1CEC423511362A9BACB3F09FC55E27AE0A5E72DD11F524F68852AC3DD3E2B7C1221C784 |
| TrID | 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1) 42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1) |
| Magika | sevenzip |
| Reporter | |
| Tags: | 7z |
Intelligence
File Origin
# of uploads :
1
# of downloads :
73
Origin country :
ROFile Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | 64位安装包_特別版.exe |
|---|---|
| File size: | 1'392'640 bytes |
| SHA256 hash: | 127dd850103b7147ece722995b407ee9e3df94d2d59cbbdb6c9613183e120600 |
| MD5 hash: | 4930d1925e4b4dcd58f08adc65095c35 |
| MIME type: | application/x-dosexec |
Vendor Threat Intelligence
No detections
Detection(s):
Verdict:
Malicious
Score:
99.1%
Tags:
dropper virus
Result
Verdict:
Suspicious
File Type:
PE File
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 cmd evasive evasive exploit explorer fingerprint installer-heuristic lolbin microsoft_visual_cc packed
Verdict:
Suspicious
Labled as:
Trojan.Win64.Agent
Verdict:
Malicious
File Type:
7z
Score:
98%
Verdict:
Malware
File Type:
ARCHIVE
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive Executable PDB Path PE (Portable Executable) PE File Layout SFX 7z
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-03 04:53:56 UTC
File Type:
Binary (Archive)
Extracted files:
36
AV detection:
11 of 38 (28.95%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
6/10
Tags:
n/a
Behaviour
Looks up external IP address via web service
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
7z ba98397db3a64b70825a4decf232fb000f3ba3ef4baae8c0519ded6f2153820b
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.