🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cde5afd20b7bb5c9457b68e02c13094125025fb974df425020361303dc6fcdfc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: cde5afd20b7bb5c9457b68e02c13094125025fb974df425020361303dc6fcdfc
SHA3-384 hash: 5cfe01cabea3c47dced1734c90c0585a0b7e87852c2a83274ab78e40db31bb3721f7143cf96ebb6ae3ac352a397fbeb1
SHA1 hash: 6da59965de973dcbb3027a43f32d3ebd178fb4c0
MD5 hash: 894981ce1257d5fd40f8c2f2119598de
humanhash: happy-september-leopard-mars
File name:cde5afd20b7bb5c9457b68e02c13094125025fb974df425020361303dc6fcdfc.py
Download: download sample
File size:25'937 bytes
First seen:2024-09-19 05:47:21 UTC
Last seen:2024-10-10 16:18:09 UTC
File type:
MIME type:text/x-script.python
ssdeep 768:2xgL6nVSKWM/Ob85E0J41VRa8tD8fUjL3sNbMwk:2OKWM/eVRDPT
TLSH T10CC2B6A13E9B5922D173C42FA9538483E31A37135A365D22F6ECD7A07FB453082B16ED
Magika python
Reporter JAMESWT_WT
Tags:95-164-17-24

Intelligence


File Origin
# of uploads :
2
# of downloads :
110
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
fingerprint masquerade
Threat name:
Script-Python.Backdoor.InvisibleFerret
Status:
Malicious
First seen:
2024-06-13 05:53:00 UTC
File Type:
Text (Python)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_decoding
Author:iam-py-test
Description:Detect scripts which are decoding base64 encoded data (mainly Python, may apply to other languages)
Rule name:Detect_APT29_WINELOADER_Backdoor
Author:daniyyell
Description:Detects APT29's WINELOADER backdoor variant used in phishing campaigns, this rule also detect bad pdf,shtml,htm and vbs or maybe more depends
Reference:https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties
Rule name:golang
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments