MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c06b48ad630de88fbc261dce8285e548231ea86aeee43ebf87c5194569129f7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 7


Intelligence 7 IOCs YARA 9 File information Comments

SHA256 hash: c06b48ad630de88fbc261dce8285e548231ea86aeee43ebf87c5194569129f7a
SHA3-384 hash: 28f9c0d3b40d7d63f74aa3faa8b6843f6fb3af33d0e83949ea39f3788f688800f5e418405ca90812713248348c2f43a8
SHA1 hash: 61bb8903268b97b6a84e57229a9a0d1a8c8acfc8
MD5 hash: 46ef4a9cb89da3e66c7725b43f82b85b
humanhash: five-twenty-lactose-magnesium
File name:us01.zoom-connect-invites.us.zip
Download: download sample
Signature ConnectWise
File size:9'814'465 bytes
First seen:2026-08-11 17:06:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:Exmdt7jwgFK3k5gv/AgKgsvm8WnMiNwLQjTKEgNqeNQQVX0gXf:8mdZjN+KgQmmiqQPKWeGSX9
TLSH T145A6336E23A3D8AF888055A701D43585222774F490DBD3D89CB2BFDFEE96049FC66607
Magika zip
Reporter BlinkzSec
Tags:ConnectWise

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
ES ES
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:index.php
File size:53'798 bytes
SHA256 hash: 11951bd03c605bc177a25ed5137fa7d56835264865329a4ebfff94b04252adda
MD5 hash: 32147ffb198c05460ae9ed42b92094c6
MIME type:text/x-php
Signature ConnectWise
File name:microsoft.php
File size:46'058 bytes
SHA256 hash: c8934a14c5182ae48fb1d91c13a67506bd4118405e0e48aafecf9b4af21a46cd
MD5 hash: 12da9c0fbb794dd0ea510875e84be17d
MIME type:text/x-php
Signature ConnectWise
File name:index.html
File size:1'527 bytes
SHA256 hash: 1694ea80f8daf98ccd45b9fdc5a5443ce4bdb74c7534abc3f1f24004bdc4111f
MD5 hash: 01e8a01f578083410072f80a2ad9008b
MIME type:text/html
Signature ConnectWise
File name:ScreenConnect.ClientSetup.msi
File size:10'223'616 bytes
SHA256 hash: 6fd88bbb11e34b00184a64bfb96bae0d59d9935ab4de22fd9cbad098106336e2
MD5 hash: e075e31bc2f84de1a6e2f04712c570c3
MIME type:application/x-msi
Signature ConnectWise
Vendor Threat Intelligence
Verdict:
Adware
File Type:
zip
First seen:
2026-07-02T18:20:00Z UTC
Last seen:
2026-08-11T15:15:00Z UTC
Hits:
~10
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-02 22:09:15 UTC
File Type:
Binary (Archive)
Extracted files:
187
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
backdoor discovery execution persistence privilege_escalation ransomware rat
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:flashakacoder_kit
Author:Lenny-3BO
Description:FLASHAKACODER PHP banking kit -- operator tag + admin chain + Telegram exfil + HTML form-action
Reference:hunts/flashakacoder-tarrarat-cluster
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:INDICATOR_RMM_ConnectWise_ScreenConnect
Author:ditekSHen
Description:Detects ConnectWise Control (formerly ScreenConnect). Review RMM Inventory
Rule name:NET
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectWise

zip c06b48ad630de88fbc261dce8285e548231ea86aeee43ebf87c5194569129f7a

(this sample)

  
Delivery method
Distributed via web download

Comments