🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bec11cab73d5b10e77bf5a019b61b076464e86751f35c351aa0af884e033dc7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments 1

SHA256 hash: bec11cab73d5b10e77bf5a019b61b076464e86751f35c351aa0af884e033dc7c
SHA3-384 hash: 507657aa335549dd44f58924bcb3a89fe8da9872bdba5a67b5ae4210c64284fff5b3918d20c9d35f76a89918d37584a9
SHA1 hash: 5ca6f136fba55a10a691a9b82eb6a0d56d863244
MD5 hash: 1d75df9619d0fd5be6bf10d2a72f0f01
humanhash: speaker-pip-fifteen-pip
File name:SOCIAL-SECURITY-benefit-statement2026.zip
Download: download sample
File size:672 bytes
First seen:2026-09-20 20:28:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12:5jszPRdR9oUu+ZPj71MEOh93iCc0OG3pX0nD2C/3L6HPRAYrJaS/:9sFdR9OuMZr3C05pED2C/3L6J3J
TLSH T1AF012382FB38D337D18DF070928F4A421D092ED90F1549550ADD5C687C54CC4CCF5584
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:2026-Financial-Statements.cmd
File size:1'065 bytes
SHA256 hash: b11b1a8b15ae561e65be53b314076fc36e0982d2ec5040bc9f3774ab82c0ae2b
MD5 hash: 2f5a5048117a827002f012e2082d1638
MIME type:text/x-msdos-batch
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
Cmd File
Payload URLs
URL
File name
https://pub-ade5a8f498114bee990e8ff001f3c6e2.r2.dev/install-2.msi
Cmd File
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
expand lolbin masquerade msiexec net rundll32
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-21T11:24:00Z UTC
Last seen:
2026-09-21T19:05:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
2 match(es)
Tags:
DeObfuscated PowerShell T1027 T1059.001 T1105 Zip Archive
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-09-21 06:18:08 UTC

----->>> #RemoteAdmin
https://www.virustotal.com/gui/file/7a5c8d0127843f35839b7ecfc76c516d8283c6024bd18462d144743e08bff735/detection