MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d852a2a105a6aaafdf2292580eea27dbfd16e248d7df4f3177b0086291cae60e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d852a2a105a6aaafdf2292580eea27dbfd16e248d7df4f3177b0086291cae60e
SHA3-384 hash: 131001ac229534327565b7664ca1c6e0519e29081f09891a250c00e0222b0ac827c32fa817e1772de547a74f03e9a6e5
SHA1 hash: f704b8e1bd27e07ab99fbbae55b5cb11be6cf2a8
MD5 hash: 5d57a21f772104640a6300551b99c82c
humanhash: dakota-dakota-earth-california
File name:VscMgrPS.zip
Download: download sample
File size:24'251'670 bytes
First seen:2026-08-12 00:30:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:DAaWRHqyGtldD3hn8KQWSbrnDafgHNEzK2jFejzU9YhKaMDnyrBhsvQ3vnXso:MaGqnDdVn83P3nDaJW2pejJrtBhsvKEo
TLSH T1E837331DCD3BA584EC0732B21A662E215437D6DB0AB48875FF950C6D3CDEFA06B56C0A
Magika zip
Reporter Anonymous
Tags:zip


Avatar
Anonymous
Malware Behavior Catalog Tree
Anti-Behavioral Analysis
OB0001
Collection
OB0003
Credential Access
OB0005
Defense Evasion
OB0006
Discovery
OB0007
Persistence
OB0012
Privilege Escalation
OB0013
Communication
OC0006
Operating System
OC0008
Network Communication
IP Traffic
UDP 162.159.36.2:53
Memory Pattern Domains
microsoft.github.io
Memory Pattern Urls
https://microsoft.github.io/mu/WhatAndWhy/enhancedmemoryprotection

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
CA CA
Vendor Threat Intelligence
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
persistence privilege_escalation
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments