🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c220dc05223726c3e2bc94a6fcb681c7239170ff768a9bfe664940e378e78739. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 22 File information Comments

SHA256 hash: c220dc05223726c3e2bc94a6fcb681c7239170ff768a9bfe664940e378e78739
SHA3-384 hash: 673e13aea6e8f5cf6d0b5340352cefbd1fc8515b343d10039e67cfd308111b891545ec501410b4a9b12fcfda65cd19e2
SHA1 hash: 0f24628865950348343e10d401c89bbf54eb236d
MD5 hash: 198cef9f2cfb116cb9ff3f44ea5b084e
humanhash: snake-hydrogen-one-pasta
File name:Account statement details.vhdx
Download: download sample
File size:71'303'168 bytes
First seen:2026-09-23 16:44:45 UTC
Last seen:Never
File type:
MIME type:application/octet-stream
ssdeep 393216:wPFYDTmGYw8ykruUcFfr12GjdfDlA8oiVfW0674:ASmGYYTr/jdfLoi
TLSH T1A1F7F116BD0C5026E47E0131DAAD96FDE92D6D20272510D3A7F4793A6F72BC12E3932B
Magika iso
Reporter smica83
Tags:vhdx

Intelligence


File Origin
# of uploads :
1
# of downloads :
20
Origin country :
HU HU
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:CERT-In1506112309.EXE
File size:3'175'024 bytes
SHA256 hash: 53a4e54f23228c129e2f3d6f34ac457878e49ed2bb5ac13f05c10a55693d2dd8
MD5 hash: 9033f5bed49269403341abcfbd8244eb
MIME type:application/x-dosexec
File name:hdp.dLL
File size:9'710'080 bytes
SHA256 hash: d3ac10084a84dcbe0563829c1da44e02b7847bd219b8d76830d6132ee859f54a
MD5 hash: 5ed50097b223217e386b07efb2acb0d3
MIME type:application/x-dosexec
File name:System_Volume_Information_WPSettings.dat
File size:12 bytes
SHA256 hash: ffa5733ff90b7df9270c8dcb5333979b9cd135f5f946508a411e7130c3b63ccb
MD5 hash: 8322b2ce214f08ada29010bbf153bf3e
MIME type:application/octet-stream
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
discimage.vhdx
First seen:
2026-09-23T14:48:00Z UTC
Last seen:
2026-09-23T15:03:00Z UTC
Hits:
~10
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments