MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7a5c5145afe6c20fc4d538f379496dad11e841be83ad592fbc32ba2a48e2b4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: d7a5c5145afe6c20fc4d538f379496dad11e841be83ad592fbc32ba2a48e2b4c
SHA3-384 hash: 96e42ec8d1b2796c13e0207e8f59c1778029b78555406a3c355bee446724bec00348eb41a0614673c456a9a1038f4b4c
SHA1 hash: e7d934feb96e0cbf32aed0ec4f74d08ac94dd1b1
MD5 hash: 2287cfbbbeee694957aa4a1b5a778b8a
humanhash: football-mango-sierra-yankee
File name:ext.zip
Download: download sample
File size:81'533 bytes
First seen:2025-07-11 18:10:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:3b1VdDFY2EQJPx2FJ66POar8f5pvrxwdRJKjBbPrROJ0h+8k1t:3b1VByA9x2FJ66PPr8hpzxKRsXRYC+8o
TLSH T1CC83126F51C6329BC30BD13C914A245A03D8852876EE641D2A8FB2671E60B7F876FE53
Magika zip
Reporter aachum
Tags:crx dropped-by-SharkStealer zip


Avatar
iamaachum
http://windowsupdateorg.live/dfhbegwfisoibfu/ext.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
17
Origin country :
CZ CZ
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:content.js
File size:98'411 bytes
SHA256 hash: a5c33a17bf43f842611cdcb8b5728d586dc91d7849f38176ca29380d74e180ed
MD5 hash: 4772f24238b16a5385979f4c1aecafbd
MIME type:text/plain
File name:icon.png
File size:2'121 bytes
SHA256 hash: 4810ef89933b28ba2af960470786c21d13059ce469dd72437cf13f7666f31c75
MD5 hash: bd650c591cfc4a375dfcb78cb2f2e2f7
MIME type:image/png
File name:jsQR.js
File size:266'986 bytes
SHA256 hash: aec81b459d4e3856885fca04b497474227396ab793daedf402fd80f7b9fcc337
MD5 hash: 24a9f1fe8467e1578412b8764bac9d84
MIME type:text/plain
File name:manifest.json
File size:743 bytes
SHA256 hash: b9e6478c06f9c525135c3554316afe58a9f1ead32ecf1f9136fc6062f17f0df4
MD5 hash: f21152b978f7612b87d01dce19e19813
MIME type:application/json
File name:background.js
File size:287 bytes
SHA256 hash: 22728f9159748c8dd933ae46b26777595b040776b56fcd01f4f9d4bf7622b3d7
MD5 hash: 715145938909bcb8a3b6261a3e349898
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip d7a5c5145afe6c20fc4d538f379496dad11e841be83ad592fbc32ba2a48e2b4c

(this sample)

  
Dropped by
SharkStealer
  
Delivery method
Distributed via web download

Comments