MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebb7518454c118a727f89ef0eb2b679d7aeeb6263797a9d223353072d30d051b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: ebb7518454c118a727f89ef0eb2b679d7aeeb6263797a9d223353072d30d051b
SHA3-384 hash: 4047134e457cb08f890ceae68774e974757dc08ebd777920b7aa0137fc67b8c39801de02787b9ab3114723d8759211f6
SHA1 hash: 60fd914cbccf0c9e4e1f0e54cdaf548f23854295
MD5 hash: 8747c4620f58158ae693c69838bea94d
humanhash: oklahoma-minnesota-three-mountain
File name:create.py
Download: download sample
File size:5'358 bytes
First seen:2025-01-30 19:51:40 UTC
Last seen:2025-01-31 17:05:23 UTC
File type:
MIME type:text/plain
ssdeep 96:1u6d+u8UOBWOTjcp7XS1W9SCHXg1vXwq8X3PwP:BvTXS1W9SCHQ1vXwXX3PwP
TLSH T1CAB1359DF9614B720C68DF3CFE2A8416B842829616511F4A76B931FCEEBFC94B520346
Magika txt
Reporter abuse_ch
Tags:py

Intelligence


File Origin
# of uploads :
2
# of downloads :
143
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
expand lolbin remote
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2025-01-30 19:41:14 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ebb7518454c118a727f89ef0eb2b679d7aeeb6263797a9d223353072d30d051b

(this sample)

  
Delivery method
Distributed via web download

Comments