MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5361beadbc83b6b1ec9a2ca69626ba99bf2eabe863d4934d7b8a80ad718ec3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



YellowCockatoo


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e5361beadbc83b6b1ec9a2ca69626ba99bf2eabe863d4934d7b8a80ad718ec3e
SHA3-384 hash: 86ec0c94bad42f9922d97f3f1bb14c1bc8b62d7b6eb7bd4033ca4ed72ce442ba327b9479a40c7fac7365c39fe0641feb
SHA1 hash: 609b0229c7300c378c45fa14af244dc126f00c07
MD5 hash: cf3ca5f1fa359ce0647c1a561991d9e3
humanhash: idaho-lamp-xray-spaghetti
File name:Praxair-Prostar-Platinum-Regulator-Operating-Manual.zip
Download: download sample
Signature YellowCockatoo
File size:4'590'925 bytes
First seen:2023-05-22 22:45:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 98304:LskECK6BLV3kTcEiJZd5yiXRXVSmSGKU5pxNbsbfU7L29bU8IsYyZWX/:L1M69uoJZ1XRlQ9KpxNbsbfUSvcv
TLSH T1602633C4B7EB0ADE54C5A71E0E6288B9A48BD21E158CE2170F7592E62F47333CE1D65C
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter SquiblydooBlog
Tags:file-pumped Jupyter Polazert solarmarker YellowCockatoo zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
202
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Praxair-Prostar-Platinum-Regulator-Operating-Manual.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:114'515'584 bytes
SHA256 hash: f799e7e81b66cf7d787abc864ed82c3dc5fd2aa95c9f3d24a39c79a3741d37c1
MD5 hash: 3fd9d81c06743c2eaffce6995ff1e46c
De-pumped file size:114'510'336 bytes (Vs. original size of 114'515'584 bytes)
De-pumped SHA256 hash: cf6873f063fed5bd9d5e2bdd3d6c3f15f0ef77b2af225d54fecd41a30a2dce86
De-pumped MD5 hash: aacadcb5c0583f827cf221911b3a1c2d
MIME type:application/x-dosexec
Signature YellowCockatoo
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments