MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec5daaa22f99a54a0604b5b6d548de417fd931dc01a24e9bcfeacf36d0b0d8b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ec5daaa22f99a54a0604b5b6d548de417fd931dc01a24e9bcfeacf36d0b0d8b0
SHA3-384 hash: a9690c24b2b7d43e9e08802e89c45c725bbff30d3bad3d43381d3b0a1453d15fb91c5d9cce69c12e6eb315f4df260320
SHA1 hash: e93fb72d65c1f634e906b012fb5611b76314eb06
MD5 hash: 00603865b42347883d8deddf5ef82e92
humanhash: timing-alaska-eleven-steak
File name:pay.xml
Download: download sample
File size:668 bytes
First seen:2026-08-18 02:13:51 UTC
Last seen:2026-08-18 05:28:08 UTC
File type:
MIME type:text/plain
ssdeep 12:FH8ioNJAC7ukxGWi2jU30+0K5+A+kjaUwSIJZhG+E6:FH8j/wWi2jzkPjI3
TLSH T170014C5DE1E9DF5109B9C586F2B04504C490D0C7A1F997D6F6CE09236F20C5E395320E
Magika xml
Reporter abuse_ch
Tags:xml

Intelligence


File Origin
# of uploads :
128
# of downloads :
2
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader dropper opendir
Threat name:
Script-JS.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-18 00:35:04 UTC
File Type:
Text
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ec5daaa22f99a54a0604b5b6d548de417fd931dc01a24e9bcfeacf36d0b0d8b0

(this sample)

  
Delivery method
Distributed via web download

Comments