MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c957c840bae1205c56c40f05342cb8da124ee7d324e800fd26f9b0dbbfd2c5d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: c957c840bae1205c56c40f05342cb8da124ee7d324e800fd26f9b0dbbfd2c5d1
SHA3-384 hash: 9958a1df709856c198ffab34b43f74f7fa63d9e6d9519dc8231c6335e6e6535ef03a61b665e4703cb168b4f2df81dc0d
SHA1 hash: 970ed8b3ddedb7aff8ab80e9648071fb6ac2f4d6
MD5 hash: 23b747ff9f297bf25d37ae5c92df2b30
humanhash: delaware-twelve-happy-sodium
File name:kru.zip
Download: download sample
File size:635'786 bytes
First seen:2026-04-23 09:26:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:/r4crnqLcPQ6LImqtuVfnui31+Xr30fSkkPEhYv7pqo0:iLcPQJLuVt3Y30forjpqo0
TLSH T13CD433607C4F0C45FDCB501BAEB56138A081BE827D3EA591E9CA21CDCE475EBD09B5E8
Magika zip
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
SK SK
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:wx.bin
File size:71'938 bytes
SHA256 hash: fd7554393d30c38e62397e38751e92657ceef05d1a5f65358e7329bb5ba1a465
MD5 hash: 622900ccf7faeac9c8c702818e748c10
MIME type:application/octet-stream
File name:sw.bin
File size:417'026 bytes
SHA256 hash: 17f9dc72a12bf4df6110f746996268ee31d60603ea80e630b025d085d3ecee4d
MD5 hash: 804ba68e16978a149da4514494ea973b
MIME type:application/octet-stream
File name:xwb.bin
File size:71'938 bytes
SHA256 hash: 66adbb9ab7d9cbbfcd46d9de226e8c6ce5fa5edf419882f714541c2a534acbb9
MD5 hash: 00237000daeac4c9e3d72e4f89de68c9
MIME type:application/octet-stream
File name:ap.bin
File size:103'170 bytes
SHA256 hash: f63f07876fc2448e58b2950260f8edfc757be189fa5f8092a39cbd55605048cc
MD5 hash: 41549f7ce1f1aae6f949be07cf3fa827
MIME type:application/octet-stream
File name:pun.py
File size:3'092 bytes
SHA256 hash: 89a8c1d2be3cd9b935dee4b1b0c38a46fcca59efe383a7d36db895b4b7e26ae5
MD5 hash: 3c9fd69a94c100714a185ac681b7ebaa
MIME type:text/x-python
File name:ap.txt
File size:46 bytes
SHA256 hash: 277fbecc1ea93f998779001fcdd2adfe2220ed747642f5b772e0d68a0d86c94b
MD5 hash: b122868e1a9d41edb5f5bf8fe2405cd3
MIME type:text/plain
File name:xwb.txt
File size:46 bytes
SHA256 hash: 9f46e66782e5d3056ab5e75c26d50b0a33efd9debb007fc2ddf23cf15315ea91
MD5 hash: 2b2ead446adc06d61777c9546536a844
MIME type:text/plain
File name:wx.txt
File size:46 bytes
SHA256 hash: 04b7da4a4671c59a9164f579b8f103eb6a708dde7d747825d490e457b143e402
MD5 hash: 6e30f2aa81cfbf08d353e33344a1d3ad
MIME type:text/plain
File name:sw.txt
File size:46 bytes
SHA256 hash: dac104bf9bccf56cb0fc2fe05c8b516c64bee750b2629bf967903d0da5480a6a
MD5 hash: 261c5bfeffb6b666b513c6ae250bf815
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
infosteal
Verdict:
Malicious
File Type:
zip
First seen:
2026-04-23T07:14:00Z UTC
Last seen:
2026-04-23T19:15:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Script-Python.Trojan.Processinject
Status:
Malicious
First seen:
2026-04-23 08:50:54 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Weedhack_Family_Generic
Author:jlab
Description:Generic Weedhack family detection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip c957c840bae1205c56c40f05342cb8da124ee7d324e800fd26f9b0dbbfd2c5d1

(this sample)

  
Delivery method
Distributed via web download

Comments