🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 deb2f2f574f20967696ee2832cabece3361b14967806c109729b41fae60ccc43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: deb2f2f574f20967696ee2832cabece3361b14967806c109729b41fae60ccc43
SHA3-384 hash: b2511365d57dfc994725bae3fdafa4d71d52dd4bac3828f5c5a34716b41663ae615f43b882dca00e703c0e9b33be7f0f
SHA1 hash: 106cac259751725576434e91b9df07ac156b233f
MD5 hash: 4f3d465b971afacdbd25d4d9c4bbbd50
humanhash: march-video-bluebird-earth
File name:GlOBAlCObrAncabr.BAT
Download: download sample
File size:2'721 bytes
First seen:2026-04-09 11:33:55 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 24:seVc2BVV7r/s2r7UdZ7s0RCHB4fqZ7WvkI7scFva4TbpWKa8kMNBwv9:pVJ/rr7UpEufqwK4TtWKjEv9
TLSH T18C516C3262635C874279DC864640D4A9F5B50AFBA8B658DFF84D483C5FB131363927CE
Magika vba
Reporter proxylife
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
BR BR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_deb2f2f574f20967696ee2832cabece3361b14967806c109729b41fae60ccc43.txt
Verdict:
No threats detected
Analysis date:
2026-04-09 11:35:17 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Running batch commands
Launching a process
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
lolbin msiexec
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-04-09 11:34:59 UTC
File Type:
Text
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments