🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de958b6195ea807ae674b522a907be91331c4d12e564e3a8e8d86d8db64d33cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments 1

SHA256 hash: de958b6195ea807ae674b522a907be91331c4d12e564e3a8e8d86d8db64d33cd
SHA3-384 hash: 8381b32103ec5cb176f850dfda4c8a8641027d8c8af50a001dee6c47daaa3315098234c4b4a87a3220925478c2f395fe
SHA1 hash: d75e3e1bb2e21df20c2d4beabd168e1c60f60977
MD5 hash: d4df77efc2d7af97efdb28f5c9a335ad
humanhash: ceiling-mars-robert-stream
File name:3574378_1_-setup.msi
Download: download sample
File size:3'047'424 bytes
First seen:2026-10-04 12:28:51 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 24576:74nnnnnnnkoVYOD2nOtBkA2yxR9P1ivgvXZ4NqWzbE/de/i1j30wLcwclRcC:74nnnnnnnkbODIOtBP79C54GilTLaRZ
TLSH T1FEE53B636950614552B4A8FAAEBE5E3B785F340D1029998EFED30F86F52D6F84C02D0F
TrID 88.4% (.MST) Windows SDK Setup Transform script (61000/1/5)
11.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika unknown
Reporter sarab
Tags:ClickFix msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
EG EG
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
CAB installer wix
Verdict:
Malware
YARA:
6 match(es)
Tags:
ADODB.Stream CAB:COMPRESSION:MSZIP COM Behavior Trace DeObfuscated Obfuscated Office Document PowerShell Scripting.FileSystemObject SOS: 0.45 SOS: 0.66 T1027 T1059.001 T1059.005 VBS Execute Sub-Script VBScript WScript.Shell
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-10-04 12:29:35 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence privilege_escalation ransomware
Behaviour
Checks SCSI registry key(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
Drops file in Windows directory
Enumerates connected drives
Looks up external IP address via web service
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
Muhammad Hasan Ali commented on 2026-10-04 13:12:35 UTC

https://x.com/muha2xmad/status/2106731754916585922