MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df49a84d186d108fe2ec367f168cb6bb56af66bce347661e739e43c727575d67. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tofsee


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: df49a84d186d108fe2ec367f168cb6bb56af66bce347661e739e43c727575d67
SHA3-384 hash: 38b52167c3408a01234758767a2b125803e59be251fbfa39084771ebf6f966b968c7c5bb60edb5a6694c876bd1114475
SHA1 hash: 6bd13906b2893c993e174ea6f9b0a1c1ac55aa0d
MD5 hash: 3bd8d73863b0dce52f4249742a249159
humanhash: network-spaghetti-zulu-cat
File name:archive.zip
Download: download sample
Signature Tofsee
File size:16'585'240 bytes
First seen:2024-07-23 15:11:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:zUyUmKRNirgyVGQezoELvo1wAwMglVhLGRsvfngLWngLS:YxiUTQezoQo9pkjLG2vfnEWnES
TLSH T147F6336698A74FD1C868E63945D74F87A2ACAB0F9102C78B0724D77B3EF33B48D16950
TrID 99.9% (.ZIP) ZIP compressed archive (4000/1)
0.0% (.PIC) Bio-Rad Image(s) bitmap (2/1)
Reporter aachum
Tags:file-pumped zip


Avatar
iamaachum
https://karelyfile.com/Download+Anchhuyee+full+movie+with+english+subtitles+in+torrent.zip => https://silorgames.com/wp-content/upgrade/fr7834n029d4gv9.rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
ES ES
File Archive Information

This file archive contains 15 file(s), sorted by their relevance:

File name:data_1
File size:270'336 bytes
SHA256 hash: 81f67418012a5602c72f7cfb2b84a29c4633fdb2549b6487388731d521b1bacd
MD5 hash: 121cefe66d326e90bfd9b6997d194e77
MIME type:application/octet-stream
Signature Tofsee
File name:history-cache — копия (3).dll
File size:5'672'302 bytes
SHA256 hash: 0e266292e48292eda9f4abb937e334d5b51ce89a709b5ee1f97e09b4a1790e6a
MD5 hash: 9f0886adb1bb4e35582b24bdef68844e
MIME type:text/plain
Signature Tofsee
File name:data_0
File size:45'056 bytes
SHA256 hash: 9c20ce7b2a5cc78511d21e5bb102f54371d4767bca87fb24a94c90a5f8eb9c2b
MD5 hash: e9c17edc4acecf69f5052f2ec5ca190c
MIME type:application/x-dbt
Signature Tofsee
File name:sharedassets0.assets
File size:6'209'196 bytes
SHA256 hash: 10ea9c78f7717d43543edb075fe9dd621749a602494aa6b0632294e63e898d66
MD5 hash: 1bbb6ef6ebe9ae14718f26271197cbb3
MIME type:application/octet-stream
Signature Tofsee
File name:db-journal
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature Tofsee
File name:data_2
File size:8'192 bytes
SHA256 hash: ec1702806f4cc7c42a82fc2b38e89835fde7c64bb32060e0823c9077ca92efb7
MD5 hash: 0962291d6d367570bee5454721c17e11
MIME type:application/x-dbt
Signature Tofsee
File name:data_3
File size:4'202'496 bytes
SHA256 hash: 6f933af3d9949acd910cbfe3b795257ee8986025336c6d2583246283049230f9
MD5 hash: 0a9e5a508cf91678fc48274d047636c4
MIME type:application/x-dbt
Signature Tofsee
File name:index
File size:524'656 bytes
SHA256 hash: e1ae22649ad42631b4fa151cc63237f58e1738d0c6d34ae4a47b99b6212c62b7
MD5 hash: cb0b158f141f471f725cd00b2e76582d
MIME type:application/octet-stream
Signature Tofsee
File name:gettext.dll
File size:49'672 bytes
SHA256 hash: 911608a464a215fcf05b273d435e8f3c16e53e45176d670f9c0ac004f7da9333
MD5 hash: 880aa760d317f99dff8f0b62ccb5b867
MIME type:application/x-dosexec
Signature Tofsee
File name:db
File size:45'056 bytes
SHA256 hash: 2ef9ab8ec9e6b879a77d1d9dbe7d18a2171f50ff37e803bbd0243af1b87dcb15
MD5 hash: 4d4863ce15ec9c7dfdc50c288a2d2d1a
MIME type:application/x-sqlite3
Signature Tofsee
File name:ucrtbase.dll
File size:1'193'808 bytes
SHA256 hash: 656e7fe89e902f00e5115d23f69ffbd043d923277c5a21149f2c60e0abbb4614
MD5 hash: 6c2810f92a98551650cb268e68a12441
MIME type:application/x-dosexec
Signature Tofsee
File name:ILU.dll
File size:76'296 bytes
SHA256 hash: 1cf1841d43767fe2f28a4e2994fe77488d232ebec3fc4cde3dcef106a5274bc8
MD5 hash: aee74e686dcf044042c150a75709e367
MIME type:application/x-dosexec
Signature Tofsee
File name:File.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:754'974'720 bytes
SHA256 hash: ef6aa89a4d4dc4db41b4406f984d0269c2ef9cf9856a7f04b7c938490202109b
MD5 hash: 10440a9f266ca350272abe0099639f06
De-pumped file size:2'858'496 bytes (Vs. original size of 754'974'720 bytes)
De-pumped SHA256 hash: 1adb3b5ba962f7eb431c9440abce7dd0269b8fb3e7b4235628b2cd8f5345b016
De-pumped MD5 hash: 756a1230e7e89d4637e9487bdc01f386
MIME type:application/x-dosexec
Signature Tofsee
File name:version.xml
File size:159 bytes
SHA256 hash: 00e68d05801e95c3207dbea1e8b448ac8960be835634df108f7286e56d0706f7
MD5 hash: c6e524037a2152d1963a2c29dbfa2966
MIME type:text/xml
Signature Tofsee
File name:resources.resource
File size:6'747'328 bytes
SHA256 hash: a2b48d31a2f429f10bc5b21d334a54d5214b6b2625b99e4e2136ab5a98ff3ff5
MD5 hash: eb8aeb8c7d01e45ae2faf42eec6ed7ff
MIME type:application/octet-stream
Signature Tofsee
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
Encryption Generic Static
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-07-23 15:12:07 UTC
File Type:
Binary (Archive)
Extracted files:
33
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery evasion
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Drops file in System32 directory
Looks up external IP address via web service
Modifies firewall policy service
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:pe_detect_tls_callbacks
Rule name:PK_PUMP_AND_DUMP
Author:Will Metcalf @node5
Description:Walks Zip Central Directory filename entries looking for abused extension then checks for a file that's at least 25M and then check to see how much uncompressed size is vs compressed size

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Tofsee

zip df49a84d186d108fe2ec367f168cb6bb56af66bce347661e739e43c727575d67

(this sample)

Comments