MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e54a6ca002f007042b9752091be95e28b27938663e581c65c895ed3e69a4b616. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: e54a6ca002f007042b9752091be95e28b27938663e581c65c895ed3e69a4b616
SHA3-384 hash: c59060357ac01af96fca7b7ab7478b534e2cf67e375747e6246131f25a44b4599507399f3cc0354c556cbb87f51de465
SHA1 hash: 944d9b4d8b1ccff2c49d119970b590385beeec49
MD5 hash: 477bed44b725e0ece81eec2b61eb6786
humanhash: montana-india-mike-twenty
File name:Zoom-Installer.zip
Download: download sample
File size:2'366 bytes
First seen:2026-08-14 11:26:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:97oczd2aMKDDJdc0kqBLfJyy+48Ko6eHm5drhbV+rBaRdj:Fn8aZJ60lrb+/ZgvqAz
TLSH T19B41FB64DF89160DC155E7F7D5730D74DA89646B5606B73A59001222BF42F633F0F2C6
Magika zip
Reporter skocherhan
Tags:robert-schreoder-de us06web-zoom-frash-org zip


Avatar
skocherhan
https://us06web.zoom.frash.org/download.php

C2: robert-schreoder.de:8041

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
GB GB
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:Zoom-Meeting-Installer.cmd
File size:337 bytes
SHA256 hash: b8254863b91d845ea93af3be045a2b28544ac62fa8dd03535d98a6de25b8063b
MD5 hash: 1ff809c3133328c52dc5ac1f7943e8ed
MIME type:text/x-msdos-batch
File name:Installer.bat
File size:1'529 bytes
SHA256 hash: 8c42eb85e2e6ee31a04bedd5b57c70765469f3e4689274da430f6a1c9c692c3c
MD5 hash: 98ed9344ebefd0886e8aec9e5e703d35
MIME type:text/x-msdos-batch
File name:meetingschedule.ps1
File size:1'523 bytes
SHA256 hash: b1fd751468c10ddd7ee6ecdee853c369b3f4b2f5f4b8faa6321943c7fe6aa794
MD5 hash: b6896cf2fafd74ddd5746bf1405bbb60
MIME type:text/plain
File name:Readme.txt
File size:353 bytes
SHA256 hash: 269c455c4f3b689c514ffdadd4ce9156561b50e11dac3386dca260d7c9521f43
MD5 hash: 623a05c905115ff773d4bcee1bb11685
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated PowerShell T1027 T1059.001 Zip Archive
Result
Malware family:
n/a
Score:
  10/10
Tags:
backdoor discovery execution persistence privilege_escalation rat revoked_codesign
Behaviour
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
https://robert-schreoder.de/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:WIN_ClickFix_Detection
Author:dogsafetyforeverone
Description:Detects ClickFix social engineering technique using 'Verify you are human' messages and malicious PowerShell commands
Reference:ClickFix social engineering and malicious PowerShell commands

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments