MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eeed9e718177a645559a18e4c65cd447ce1051b2ea95a1c67035c9c3019fce24. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: eeed9e718177a645559a18e4c65cd447ce1051b2ea95a1c67035c9c3019fce24
SHA3-384 hash: 3d0ee6d14feac37ecb2bb69717b305276d39521382ee6c5cd3974d6ca3a279deffd38af199ca2930586b1e00b467aea5
SHA1 hash: d32c5301c2bdcbc2664a5b5a58edfba3c6e8cfb5
MD5 hash: 32748b1cf9dfcd1901d1053d26d96b73
humanhash: wolfram-edward-charlie-eight
File name:eeed9e718177a645559a18e4c65cd447ce1051b2ea95a1c67035c9c3019fce24.zip
Download: download sample
File size:84'999'869 bytes
First seen:2025-12-30 10:26:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:uoJ42/CQFXVIT0LqBjFGaxUR/rkaHPgu05fhVo0IRdEdoX+mn9ii+DTBunBjNrpS:rJt6cfY8axUR/rk2PkJ/oVzs9m9RPnBa
TLSH T101183354839DAB5AD23FB237803622A5EDB67409C253B9EF2A0C03D256C3FF15E56D06
TrID 66.6% (.XPI) Mozilla Firefox browser extension (8000/1/1)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika xpi
Reporter JAMESWT_WT
Tags:pingserv-pro zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc crypt
Gathering data
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Adware
File Type:
zip
First seen:
2025-12-20T05:29:00Z UTC
Last seen:
2025-12-28T19:21:00Z UTC
Hits:
~10
Gathering data
Threat name:
Binary.Adware.Generic
Status:
Suspicious
First seen:
2025-12-18 01:05:20 UTC
File Type:
Binary (Archive)
Extracted files:
1513
AV detection:
7 of 24 (29.17%)
Threat level:
  1/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments