MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfe16c8f2ecca2f95d59c123f007d93f6b01828e5f6691cb148b9fb4e96cb16d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bfe16c8f2ecca2f95d59c123f007d93f6b01828e5f6691cb148b9fb4e96cb16d
SHA3-384 hash: f612d81ac145be5f0fb931561720e6eb429daa907d4d2eae9dd12d48e977c72e920688ac7c8ae625c377e3e34819c906
SHA1 hash: cd20f4bb7f882e8b3f6db6e07535ff165699f3bd
MD5 hash: bf2f860ef202712f0e683758ef9bc059
humanhash: alpha-winter-angel-victor
File name:app-64 (2).7z
Download: download sample
File size:89'248'453 bytes
First seen:2026-07-26 11:40:59 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 1572864:le4hdV6xfMCginFt90c3Hkc7M0zLr1X3OznfxySo3RPqSlfVDWTzP:le4DoxfMCFnF7z3V7vl385ySor0TzP
TLSH T1CA183301DA96087FD22DF97CD9E3F22582D6C98BC661B56C056BC7DDED26F0A98C400B
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter JAMESWT_WT
Tags:7z Windows-Update-Assistant

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments