🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c028bc061adf89d0b570e5ac8a438dc484a1d86e3c67a030256f02ff51ebcbd2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 29 File information Comments

SHA256 hash: c028bc061adf89d0b570e5ac8a438dc484a1d86e3c67a030256f02ff51ebcbd2
SHA3-384 hash: 17ef00c1160359a2760b068934f8f28baf5deef42266359d1faa3186155030bcfb2d10d6f8582cf012f9670946ba8611
SHA1 hash: ba6645dedebec17061b781bba65f37a707f667bf
MD5 hash: 2219c4db52ff75f5dc3ad7eedf4998e4
humanhash: solar-aspen-hamper-berlin
File name:c028bc061adf89d0b570e5ac8a438dc484a1d86e3c67a030256f02ff51ebcbd2.bin
Download: download sample
File size:2'373'568 bytes
First seen:2026-10-02 19:18:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:58hKXINOf1gVgjowD9v7wMDWqLlhmEnD9UjZAcI8twWEzduklL0:uhKcq1wgjow8sMY9qZFI8twVRVi
TLSH T1F4B5339A19709098D7C41A359F9B11D4FB4F1145DA0DAA388E3DE28D70DA7F7203E2AB
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
US US
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:INIT
File size:1'536 bytes
SHA256 hash: 8ee5c1d7a199e577c0c62968d3887d9b3f0edf0499ec83011b0ee67a74e3b4ae
MD5 hash: 8e15604dc88b39e40563b6f9a26ebc5c
MIME type:application/octet-stream
File name:AMIFLDRV32.SYS
File size:10'240 bytes
SHA256 hash: b7067533886109b47f6a18edea5919c17e1c6f77ddc00d88eae8879ee4e9bcbd
MD5 hash: 453731a68c6d305c4d3bbbce684d148c
MIME type:application/x-dosexec
File name:AFUWINx64.EXE
File size:1'027'696 bytes
SHA256 hash: fc8085a1a2686d919c4b9723f2623866c2840db2f9ee873142eeb32af3872db1
MD5 hash: 136e8c1ddfd503af432b4dd942f892d6
MIME type:application/x-dosexec
File name:amigendrv32.sys
File size:16'056 bytes
SHA256 hash: de577ea8251b763f42be9fc548aea06db5f4aa68a7a2bf079a3cc0df20c6c5c5
MD5 hash: 1a5e219d8f4988b3ae4549eea66483b0
MIME type:application/x-dosexec
File name:DMIEDITx64.EXE
File size:3'374'704 bytes
SHA256 hash: 06bb8a47a5cdf76b8714be12f047eb65d52ff906b16881b6574a18afc34c57c9
MD5 hash: 728048ee156ce6baecc7caf9e5fcdb03
MIME type:application/x-dosexec
File name:AFUWIN.EXE
File size:641'136 bytes
SHA256 hash: 9b508e1478377cd5dc8be10a14f141378bcf4b4b5d3afb1371f3d6fce044b5cd
MD5 hash: e1da4f8b7b9f982738b340fcba2c3028
MIME type:application/x-dosexec
File name:AMIDEWINx64.EXE
File size:386'672 bytes
SHA256 hash: 47c16703fa7df006f9559fca8b1482b4c59111017a0530c1edac3caf0bdaaf39
MD5 hash: 6dea36ae7a414e376b00829e16da52e0
MIME type:application/x-dosexec
File name:amigendrv64.sys
File size:37'040 bytes
SHA256 hash: 811e5d65df60dfb8c6e1713da708be16d9a13ef8dfcd1022d8d1dda52ed057b2
MD5 hash: 9accebd928a8926fecf317f53cd1c44e
MIME type:application/x-dosexec
File name:AMIFLDRV64.SYS
File size:29'776 bytes
SHA256 hash: 65c26276cadda7a36f8977d1d01120edb5c3418be2317d501761092d5f9916c9
MD5 hash: f22740ba54a400fd2be7690bb204aa08
MIME type:application/x-dosexec
File name:AMIDEWIN.exe
File size:307'312 bytes
SHA256 hash: da35eabcd2ae42e0fe975454464eaef167156078e1260222127338ebc6e54473
MD5 hash: 2b34156ed9893c771720273727607535
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug fingerprint lolbin microsoft_visual_cc overlay reconnaissance rundll32
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-25 14:30:43 UTC
File Type:
Binary (Archive)
Extracted files:
59
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery execution
Behaviour
Suspicious behavior: LoadsDriver
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:drv_MmMapIoSpace
Author:h_s
Description:Detects MmMapIoSpace import from NtosKrnl.exe
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PUA_VULN_Driver_Windowsrwinddkprovider_Amifldrvsys_Windowsrwinddkdriver_38D8
Author:Florian Roth
Description:Detects vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - amifldrv64.sys, amifldrv.sys
Reference:https://github.com/magicsword-io/LOLDrivers
Rule name:signed_sys_with_vulnerablity
Author:wonderkun
Description:signed_sys_with_vulnerablity
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_VulnDriver_Amifldrv_e387d5ad
Author:Elastic Security
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks
Rule name:WIN_Malware_ACRStealer_ForgeAuto_1084c837_Extrait
Author:Marjoriefort
Description:Detects ACRStealer (pe, etat extrait)
Rule name:WIN_Malware_Ceber_ForgeAuto_8b9c7147_Extrait
Author:Marjoriefort
Description:Detects Ceber (pe, etat extrait)
Rule name:WIN_Malware_Cerber_ForgeAuto_b3e1e9d9
Author:Marjoriefort
Description:Detects Cerber (pe, etat binaire)
Rule name:WIN_Malware_Fantom_ForgeAuto_98e6f354_Extrait
Author:Marjoriefort
Description:Detects Fantom (pe, etat extrait)
Rule name:WIN_Malware_PsychedelicStealer_ForgeAuto_14838da1_Extrait
Author:Marjoriefort
Description:Detects PsychedelicStealer (pe, etat extrait)
Rule name:WIN_Malware_PythonStealer_ForgeAuto_b24cb5bd
Author:Marjoriefort
Description:Detects PythonStealer (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_1762e598_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_2e3a5916_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_30f84f37
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_37b4704b
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_74566f98
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_79234c04
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip c028bc061adf89d0b570e5ac8a438dc484a1d86e3c67a030256f02ff51ebcbd2

(this sample)

  
Delivery method
Distributed via web download

Comments