MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c603da7b4938df42e73b43b9a870c968f2c53fafb2914fb70dfd9cd24959f6db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | c603da7b4938df42e73b43b9a870c968f2c53fafb2914fb70dfd9cd24959f6db |
|---|---|
| SHA3-384 hash: | 1d2d391294badf446770a0656cea22687796b82273aa222e37ab580cffd8cc9902d55f736939c78e8a4c23e35c11dbe5 |
| SHA1 hash: | 89c015ed59b463f9d8d31387c3933769e492feb9 |
| MD5 hash: | 0cf7185d6950135d22418434c39fec8e |
| humanhash: | mexico-hotel-london-march |
| File name: | RADCUI.zip |
| Download: | download sample |
| File size: | 12'952'489 bytes |
| First seen: | 2026-08-11 23:57:19 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 393216:pPJUmzfrVSwKm8rFoUwLXG/SIHgpyMdfga:pFrwbSLW/UZoa |
| TLSH | T1FDD633B74861455FDC2FE573DE8FCF24968BE12C8D2068120970BE673A1D9716ACB24E |
| TrID | 66.6% (.XPI) Mozilla Firefox browser extension (8000/1/1) 33.3% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | zip |
| Reporter | Anonymous |
| Tags: | zip |
Anonymous
Activity SummaryDetections
NOT FOUND
Mitre Signatures
2 MEDIUM 11 LOW 9 INFO
IDS Rules
NOT FOUND
Sigma Rules
NOT FOUND
Dropped Files
1 PE_DLL 1 TEXT
Network comms
1 IP
Behavior Tags
checks-network-adapters detect-debug-environment long-sleeps
MITRE ATT&CK Tactics and Techniques
Search for technique, subtechnique and in its matching entries
none
info
low
medium
Execution
TA0002
1 Techniques
Hijack Execution Flow
1
T1574
Privilege Escalation
TA0004
1 Techniques
Process Injection
2
T1055
Stealth
TA0005
8 Techniques
Process Injection
2
T1055
Indicator Removal
T1070
Indirect Command Execution
1
T1202
Virtualization/Sandbox Evasion
2
T1497
Impair Defenses
T1562
Hijack Execution Flow
1
T1574
Discovery
TA0007
4 Techniques
System Owner/User Discovery
1
T1033
Process Discovery
1
T1057
System Information Discovery
5
T1082
Virtualization/Sandbox Evasion
2
T1497
Command and Control
TA0011
1 Techniques
Application Layer Protocol
2
T1071
Malware Behavior Catalog Tree
Anti-Behavioral Analysis
OB0001
Collection
OB0003
Credential Access
OB0005
Defense Evasion
OB0006
Discovery
OB0007
Impact
OB0008
Execution
OB0009
Persistence
OB0012
Privilege Escalation
OB0013
Communication
OC0006
Operating System
OC0008
Intelligence
File Origin
# of uploads :
1
# of downloads :
30
Origin country :
CAVendor Threat Intelligence
Score:
0%
Verdict:
Benign
File Type:
ARCHIVE
Gathering data
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
defense_evasion persistence privilege_escalation trojan
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Delivery method
Multiple
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.