🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb
SHA3-384 hash: f840d2488c3474a43d421c725f5bb02365a31e1b03c2f4bb0e9b613ea7f887f773e8706349050f77f8b9bb3b06e9ec6a
SHA1 hash: cfe16ea87f4d2402fa836284a7201c4cf3c0a345
MD5 hash: ab917b4d771e88c6313e58cf1e0b0442
humanhash: mexico-potato-north-lion
File name:ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb.bin
Download: download sample
File size:693'163 bytes
First seen:2026-09-12 06:18:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:CKD92vPyY7v73lFw/xs5XU/03I9YuNg7ItRLtEdamN2LN/Ozzwb0XN6W6M:Fapv5Fw/mdU/UI9Y+wERLS/0/YzLdSM
TLSH T125E433AFAA996B62F71902F352C1BDDC106C3B1A52652CB3D6201CDD0FBF1E8B871654
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
US US
File Archive Information

This file archive contains 17 file(s), sorted by their relevance:

File name:Assets.car
File size:481'672 bytes
SHA256 hash: a7c0ed97cf544046e0bbce271dc52652a90bddd20dbd7f68363bf0d2e12a410b
MD5 hash: 3de1b31280664b714dcd65b7caa4a134
MIME type:application/octet-stream
File name:pass-show.svg
File size:887 bytes
SHA256 hash: 56d3dd8c42329c635a6552787382a8709cfeb6b823890844c85a04d7c1037379
MD5 hash: d7350c60b02405911ef4ca6d38e4dab1
MIME type:image/svg+xml
File name:login_bg_top.svg
File size:2'277 bytes
SHA256 hash: e065a6bd47f72ed9916a6b451c76121169d7860e8b26a83d104c9b4a7271747a
MD5 hash: 21a48933472b940c8fd1a3845b2070be
MIME type:image/svg+xml
File name:lock-wallet.svg
File size:5'930 bytes
SHA256 hash: a3860cdeaec2655e11f5cbe8996f6a5a367301d6337fa1e321b23e03cfd29112
MD5 hash: 1850fc30305da1c852876c8fe3e33279
MIME type:image/svg+xml
File name:end.html
File size:3'422 bytes
SHA256 hash: 900e4c396422350159e02e1c48a7c802b47d4108cd96fe2281dd9798f8d31903
MD5 hash: 2b3357269c3e4ce85ba9818de5e25544
MIME type:text/html
File name:login_bg.svg
File size:2'035 bytes
SHA256 hash: 882cb65a3e75639e9e8f9b70a6d85bad26c1e0e3cd64de566a703b7191a05203
MD5 hash: 355adee51eaa8c821b76fe9dca25f5dc
MIME type:image/svg+xml
File name:Exodus
File size:262'192 bytes
SHA256 hash: 8d88b558dc9edbc4fdb66eb2451fd5f4df49266921346d2db1191cf23f0d13dc
MD5 hash: cd4b6ef640ebcb61037d0ea64a371c24
MIME type:application/x-mach-binary
File name:bip39-words.js
File size:17'239 bytes
SHA256 hash: 3037d0155d2c2b68950b1641ab521656a6a73f7c5ce91bda9315eb70f3312ab9
MD5 hash: 001a0dc46a83c8a4850c36e1c5231338
MIME type:text/plain
File name:exodus-logo.svg
File size:1'487 bytes
SHA256 hash: 67c6bc473a156f82f89abd20ee0e36b5962e0c7bf9851f805987fad3d8161a84
MD5 hash: 019345a05724d5728788f9ea2e2b830f
MIME type:image/svg+xml
File name:AppIcon.icns
File size:67'376 bytes
SHA256 hash: ddf65bf7c48a1b78e16305c4a41194ce479f54816d4a7d54b58b125d5e8f30fc
MD5 hash: 5dd0b850f81c06bef0776b9d83a3fd5b
MIME type:image/x-icns
File name:index.html
File size:18'975 bytes
SHA256 hash: b926056ed7e5407ab94229f16887f6e8520d3a4263476d5fa012fdb325d797c7
MD5 hash: 5e9286cb25a781f64baeed7950c92799
MIME type:text/html
File name:Info.plist
File size:1'538 bytes
SHA256 hash: 3c2913b6fd35de686423fdfef3dca958a2ceaaa28d5d7c2aff7b2357f2f4dcbc
MD5 hash: 3c4c0f53c28af07d705c0a1c02182ba1
MIME type:text/xml
File name:PkgInfo
File size:8 bytes
SHA256 hash: 82502191c9484b04d685374f9879a0066069c49b8acae7a04b01d38d07e8eca0
MD5 hash: 23b7d7d024abb0f558420e098800bf27
MIME type:text/plain
File name:CodeResources
File size:5'228 bytes
SHA256 hash: ee035349875e026a043bed7b85aa3d56ac66bd54401025418a551acf911d8b08
MD5 hash: d6118bc571ac624ad2c002835a75ced0
MIME type:text/xml
File name:put_seed.html
File size:27'273 bytes
SHA256 hash: b967d4b8977344ec236508014e36e5814fe6aca9ca4bcbb2f575d176a400e8c6
MD5 hash: 1db330cff59e59f9c1d30cf0c5673abf
MIME type:text/html
File name:pass-hide.svg
File size:1'355 bytes
SHA256 hash: 15a001cf28a54f649fef4443c2331ddbd7d38ce66e13bacc265fc251f9135f17
MD5 hash: 55665556515c9bf208626a6ab3839049
MIME type:image/svg+xml
File name:login_bg_top.png
File size:70'408 bytes
SHA256 hash: e461fcdd431b064f7ddbe06ff8d0ad01f0d259522f81709fae0110d28f21d4bc
MD5 hash: 53c3bd1898fb3fc6a3539d6c183066c5
MIME type:image/png
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-09T13:33:00Z UTC
Last seen:
2026-09-09T15:34:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
SVG Zip Archive
Threat name:
MacOS.Infostealer.Generic
Status:
Suspicious
First seen:
2026-09-10 02:27:56 UTC
File Type:
Binary (Archive)
Extracted files:
38
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion macos
Behaviour
Resource Forking
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb

(this sample)

  
Delivery method
Distributed via web download

Comments