🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5db35dfa6dc550a9cf6b53586672410a2a08df31979d2141933b59cbf5116da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 15 File information Comments

SHA256 hash: d5db35dfa6dc550a9cf6b53586672410a2a08df31979d2141933b59cbf5116da
SHA3-384 hash: b0db9887e8608d677affa6a4eca0a5f8046ebf7bddbe53b66b65b17be95b6cff00604241a7d528a089932c48c325afaf
SHA1 hash: b1342ca30f841542b67d238ee7cf473e12d0b54d
MD5 hash: 1adb634b0b498a770a19f53788ca4039
humanhash: september-enemy-ten-carolina
File name:EXE A ANALIZAR.zip
Download: download sample
File size:13'616'515 bytes
First seen:2026-09-14 21:44:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:GZbZYPz4gd3mH0TPS1+oU0Ao130QNSEw3OM3oboJhEFR:YbePzvPS1nmoN04SN3OWJhEj
TLSH T19FD633AD546058E4E3E1E47AD3AF9D1B901D80C7B2FA26C31EFE6D94E85F80EE5C5090
Magika zip
Reporter cypherpunk472
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
CO CO
File Archive Information

This file archive contains 32 file(s), sorted by their relevance:

File name:CP210xVCPInstaller_x86.exe
File size:924'408 bytes
SHA256 hash: 8d94e8dd8eed18c8ab2808f6c2186e57aab4c5bcd93628ec1f14cbd330c7b7c2
MD5 hash: 6f2086a88cbb67d847e4527903fd48fa
MIME type:application/x-dosexec
File name:CP210x_Universal_Windows_Driver_ReleaseNotes.txt
File size:23'023 bytes
SHA256 hash: fa90c322add4d151cdf8fdeb82d84c59f8351821ece0026b94e25c386cdcfabd
MD5 hash: 84b0b5582364c73cd34a1e36e338c59e
MIME type:application/octet-stream
File name:MSCOMM32.OCX
File size:103'744 bytes
SHA256 hash: 51a1d6812e445c26c71465e2709e6d1ad587f8513002d662cd160f424f48b37c
MD5 hash: 2c6119da3993f410e74b15112f840cb0
MIME type:application/x-dosexec
File name:silabser.cat
File size:12'629 bytes
SHA256 hash: 0a915ba72b2ff16b630999bbbb476c34482076529b53442b56b519bfc7ebfc12
MD5 hash: c2dcb6268a4b30cb4a375fcfa26145d9
MIME type:application/octet-stream
File name:slabvcp.cat
File size:10'970 bytes
SHA256 hash: ae47b51d0c97ecd82c2e196f9005f914a41504e8bbd1e9fec6ee007afe743fd3
MD5 hash: 37d19dfe0a682bf4a3ca21966bff788d
MIME type:application/octet-stream
File name:RHT20.msi
File size:577'544 bytes
SHA256 hash: 5138fe66c136c27fe19bfd8185d1ad8b66f75fd6b200b630148df4561c6237ff
MD5 hash: d3a887de8262a8ad26fa8339fd812436
MIME type:application/x-msi
File name:v6-7-6-driver-release-notes.txt
File size:15'553 bytes
SHA256 hash: d49596d4c2e4931701f276961a6619441a1e5a0fefda078a6b5ca7be8de44b64
MD5 hash: 6575e3e6be16f02aef66f6f6b8e8ead5
MIME type:application/octet-stream
File name:setup.exe
File size:356'352 bytes
SHA256 hash: fc3e58459da02453f3e5d60cda814cabe03027cd274a44252f4706173ab520ac
MD5 hash: 978fa8030ca1df5e287c6925719112b8
MIME type:application/x-dosexec
File name:WdfCoInstaller01009.dll
File size:1'470'704 bytes
SHA256 hash: 760f934b8fbbb7dcf0a3748c23c12ca503a23493b01d36cd0a85bd14ef2d123e
MD5 hash: 896678214e511e8facc4e6e9007468c2
MIME type:application/x-dosexec
File name:WdfCoInstaller01011.dll
File size:1'629'040 bytes
SHA256 hash: c7649879a10c9332fc0f9744c7e3224647aee9e7e62c7e21cf9e987462e3dd06
MD5 hash: 3d2a2d921135801835073451f002480f
MIME type:application/x-dosexec
File name:silabser.sys
File size:85'384 bytes
SHA256 hash: 2de1b936d37f82cba93a5c6e04b30199a47f04751e4f21d10f0bac3e0c3ed7b0
MD5 hash: d729b85e94f4ebaf2345f8f313d0046a
MIME type:application/x-dosexec
File name:RHT20.exe
File size:1'007'616 bytes
SHA256 hash: be585de84e564b004fae63e0c2eafbff0dac7695293f95b0f9ede65483cf95b6
MD5 hash: 9c3d61c7b5fbb26bc8caeac6f0dd105e
MIME type:application/x-dosexec
File name:Help.chm
File size:2'291'716 bytes
SHA256 hash: 32adbc49d0ba4234743a75a53d5f0dbaab1c41282b8d3451c9af006fa575070c
MD5 hash: 4559528545876078fb4349c48a401adf
MIME type:application/octet-stream
File name:ExtechInstaller.exe
File size:1'057'280 bytes
SHA256 hash: c9ab80a1d3cfcdc17c2327362b08e754fd4af20da8a983478d90b1bef022f728
MD5 hash: 85adcf7d903137446f2f430b2c23483a
MIME type:application/x-dosexec
File name:CP210xVCPInstaller_x64.exe
File size:1'049'848 bytes
SHA256 hash: 01a3b9e1ce2104c58a32cfb199bb4577012f71fcd54d3eeb3483461680d29406
MD5 hash: 79d16a2306eb75daabdccfa80b9fd5a1
MIME type:application/x-dosexec
File name:RHT20_UMfr.pdf
File size:398'737 bytes
SHA256 hash: 1eef554d61d2968b5b0a714c9865e0863b529f438aa11c4d26739dd72b78cd7d
MD5 hash: 60ffc9197a5751c88384f91b0c8a1ebb
MIME type:application/pdf
File name:ExtechInstaller.exe.config
File size:296 bytes
SHA256 hash: d2ee01a586536512221b495058c92092fd87023f364017d3ea7308152b2e43e8
MD5 hash: d684f7e1872ef8d5a58d03ff60cdd3af
MIME type:text/xml
File name:dpinst.xml
File size:11'568 bytes
SHA256 hash: baf20fde8e8283f6f21098aeed53d1d8b86c13a99e1816b594f8ce9d6fc83092
MD5 hash: 869039ea5bd8ac4d25ffe350e9dc617f
MIME type:text/xml
File name:MSCOMM.reg
File size:395 bytes
SHA256 hash: 305a51a3596399162b749182e140a3f7057399a22b32609ba6a48d01caf2b711
MD5 hash: 7203f3080fd01278195dbbaebc5233a9
MIME type:text/x-ms-regedit
File name:RHT20_UM.pdf
File size:385'194 bytes
SHA256 hash: 03d5f774749e90b6c37353237965967458be6d51377bb5eafe8c09a9d2ba126a
MD5 hash: e644cbe9b36e49d37638c9b3b36ca54b
MIME type:application/pdf
File name:RHT20_UMpt.pdf
File size:392'476 bytes
SHA256 hash: a9007aa43f39ad75f25cca7d66bb09a25358f227ff20fb1ebb2d0fa948c34b9d
MD5 hash: 3acb31536e6606bd377cab257112e67b
MIME type:application/pdf
File name:RHT20_UMsp.pdf
File size:387'111 bytes
SHA256 hash: 952808d265febb672dd7cea10706dfd0642af515a40027e7a77034f20628f4d4
MD5 hash: 82a388e1be2954eb8c4af4f85688ced1
MIME type:application/pdf
File name:RHT20.exe.manifest
File size:621 bytes
SHA256 hash: 96769bfc065802cebb8a84900d9b91fe40d4c18d713b6320dbf725b0bb351377
MD5 hash: dc9a16ff8643f6a6225aff2e189117f1
MIME type:text/xml
File name:Configure.txt
File size:668 bytes
SHA256 hash: f80059ff0b227771fe4e417b27eae8391470b3b2ec2d6fd092628d30b771d6dc
MD5 hash: 5da0e8cb4756619007d14a346ab53880
MIME type:text/plain
File name:slabvcp.inf
File size:7'509 bytes
SHA256 hash: 9b4ddf8f4a513d3d32d7a6a6922d445cff17ea41d952e591f93b74d17b94d18a
MD5 hash: 5ab148e9238b8c4e1eefc77439739e7b
MIME type:application/x-setupscript
File name:RHT20_UMge.pdf
File size:395'736 bytes
SHA256 hash: 504c2b8b6eca6b2f97c8c8294cf26700e795befab6bfd914b6b60108a4102d16
MD5 hash: fe0a94309180b0c9c4775f150c95ebb6
MIME type:application/pdf
File name:Setup.ini
File size:2'730 bytes
SHA256 hash: 790c948fc2794c7fbfe1f3d2f49f9e37b8c30867bb5fbda2572c8b7e20a21494
MD5 hash: e8b8167a9f13518a328d10741293712b
MIME type:application/x-wine-extension-ini
File name:USB_Driver_Setup.bat
File size:1'088 bytes
SHA256 hash: e6a1386ee10950d1585d66d602898b2c9e4163909088d56b51ea6107481d1497
MD5 hash: 2849df055c2df76929ed0b662d96340c
MIME type:text/plain
File name:0x0409.ini
File size:6'187 bytes
SHA256 hash: 2a5eb805543b141d77ce7192c5f7e4e10ffb56de0a5a66905c79298dfc5ffbd5
MD5 hash: 26a9b54f250e00693773481b837e03cc
MIME type:application/x-wine-extension-ini
File name:silabser.inf
File size:10'068 bytes
SHA256 hash: 8a992eb5271a99688e69a3db6647889c4404e6a4140981e86aed68ac841da5c6
MD5 hash: 2c57513804f727c82a05c02bc3dd3dfa
MIME type:application/x-setupscript
File name:RHT20_UMit.pdf
File size:382'247 bytes
SHA256 hash: 7039a64a3f9abb63865a047ea5a3f15777bc52d883e63884cdeb28d0ba8ce7cc
MD5 hash: bb75c6c0648a4266d0f01e2b4a14e203
MIME type:application/pdf
File name:SLAB_License_Agreement_VCP_Windows.txt
File size:8'370 bytes
SHA256 hash: 22fecb982248292fb7d4347252106274f036dc100e388343910bf671e93ac009
MD5 hash: 3e6dac7821d07f919a38df90b86e3c78
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Clean
File Type:
zip
First seen:
2022-10-21T18:45:00Z UTC
Last seen:
2026-09-14T13:09:00Z UTC
Hits:
~10
Gathering data
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2022-11-02 19:37:15 UTC
File Type:
Binary (Archive)
Extracted files:
36870
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:CHM_File_Executes_JS_Via_PowerShell
Author:daniyyell
Description:Detects a Microsoft Compiled HTML Help (CHM) file that executes embedded JavaScript to launch a messagebox via PowerShell
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:mht_inside_word
Author:dPhish
Description:Detect embedded mht files inside microsfot word.
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TH_Generic_MassHunt_Win_Malware_2025_CYFARE
Author:CYFARE
Description:Generic Windows malware mass-hunt rule - 2025
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments