MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 edbf993b48fa8ce321637fb3ec609a28687de0b56979a90a08cc8ca4f4aa3ac6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments

SHA256 hash: edbf993b48fa8ce321637fb3ec609a28687de0b56979a90a08cc8ca4f4aa3ac6
SHA3-384 hash: 9fb3c0e21e11c9375c1da892ab32c10f4627adc053677d9a79e8d61afdd2f3b9ed988333b09d982045730455a159269c
SHA1 hash: 8e7f1618a672772a7c2b38de8aa7bbc47b6a3b37
MD5 hash: f4ca7289e90e47a2fc9f4e0dd9c6058b
humanhash: crazy-pizza-whiskey-foxtrot
File name:Secure.au3
Download: download sample
File size:2'696'599 bytes
First seen:2024-10-11 21:12:05 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 24576:qc1h8yNhDwcnic6z+I7wKFoLKvpOlGzADkmW1v1tLi:h
TLSH T118C55BF771EA00C1CA2279C15DA673863A3471B7CFC5C45C392F568CEB66CAAC1C6A64
Magika powershell
Reporter aachum
Tags:au3

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Clean
Score:
89.3%
Tags:
vmdetect
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-vm masquerade
Result
Verdict:
UNKNOWN
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

edbf993b48fa8ce321637fb3ec609a28687de0b56979a90a08cc8ca4f4aa3ac6

(this sample)

  
Delivery method
Other

Comments