๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1131dc6bbbfa8054b0f3d0c07fb220bb1eb613921ced4bbed909fd4a8b69238. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 32 File information Comments

SHA256 hash: f1131dc6bbbfa8054b0f3d0c07fb220bb1eb613921ced4bbed909fd4a8b69238
SHA3-384 hash: 98a0130e4f8ffcb4d5a4612fc769bcb78a9d16f8b3718ffab97758be595e2cc66b8486f178a045350c29f00f1bd93855
SHA1 hash: 13b419e0f4de291457f82495f62a11b69483ae71
MD5 hash: 9ae185944b145663a69a004fe7cecdf9
humanhash: mockingbird-nuts-mango-mango
File name:propertyconcentrate.zip
Download: download sample
File size:1'365'512 bytes
First seen:2025-04-03 14:38:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:MxnQta7mK2hPpUFIR/uknjiqr27ylc78JRZ3RLnI3cg4nXJdhyQUuO8CFDl1Vg:knvF2r/u2Nr27978HGUEQW9Fg
TLSH T1755533A8CBE84D056E3C12B523869D52D534F640AD7C8BCA8B40853785AF1B4CF2F7A7
Magika zip
Reporter JAMESWT_WT
Tags:195-82-147-81 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
IT IT
File Archive Information

This file archive contains 13 file(s), sorted by their relevance:

File name:api-ms-win-crt-heap-l1-1-0.dll
File size:31'336 bytes
SHA256 hash: 40ce7c3bd29c145f9537ec334fd05c2650255da5617ac5f20699968ea05ffc10
MD5 hash: 880fe8b5816ff7aa9edb70b0460eda2f
MIME type:application/x-dosexec
File name:api-ms-win-crt-string-l1-1-0.dll
File size:36'976 bytes
SHA256 hash: e822dd071a176c232e061fe55f47ddf9c54d11dfc01140bb9174bd5dd6d0666d
MD5 hash: cda171611401dae268143e0855550abf
MIME type:application/x-dosexec
File name:VCRUNTIME140.dll
File size:110'528 bytes
SHA256 hash: e429a6ec76ac249e942b94406a95463d6323769ebff11af6be8c828a219f14fa
MD5 hash: f6bca8d07fe9f8a9051f245fd1208995
MIME type:application/x-dosexec
File name:api-ms-win-crt-math-l1-1-0.dll
File size:40'048 bytes
SHA256 hash: 85b0eb99620c45fd1dea34061a9ad17c5b7944e8aa1fac680432ffae4aaf2f8c
MD5 hash: 130e0a664d187c84447912bc681588d4
MIME type:application/x-dosexec
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:32'888 bytes
SHA256 hash: 57f0b83d6b9d17094538915117a41a85abe04671e56b132ab6a3b8af8811844c
MD5 hash: 94e4024feeae519b9bd58d87e39a4611
MIME type:application/x-dosexec
File name:propertyconcentrate.exe
File size:25'496 bytes
SHA256 hash: 7d065315846b9a07a23d89789732dcc148e038584d28c95df08b9c8a5d9eb01b
MD5 hash: 6481f45b72f41372ded2a64eb33f1c7e
MIME type:application/x-dosexec
File name:api-ms-win-crt-stdio-l1-1-0.dll
File size:36'968 bytes
SHA256 hash: ae47f43cb90d95dfa4f97ac87ebd899f54c99c18ac90b41259f5639888394f74
MD5 hash: fab429e0fabf51f5d6f5d0182baa74de
MIME type:application/x-dosexec
File name:api-ms-win-crt-runtime-l1-1-0.dll
File size:35'440 bytes
SHA256 hash: 8b337dbfb8be5042fdd744d8806c1f79caec9e79fb82f3032392615427b3843f
MD5 hash: d41fa685d914f811ba43cca106d9258e
MIME type:application/x-dosexec
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:34'928 bytes
SHA256 hash: 8153472f9f19dfb13a0c62c3e2aa303f7d1fce5b9cf14a43c7c6d3de1f46f148
MD5 hash: d9bddb4eb3fefe4e66b4ff59a0b54b93
MIME type:application/x-dosexec
File name:nasrallah_x86.dll
File size:25'613 bytes
SHA256 hash: d385042a7b77ab3580f49e003320655d01ee00d3e933497d2fc2dc4337e6fe5f
MD5 hash: ae65dc8ac6eca43fed93b58c80e1cfa3
MIME type:application/octet-stream
File name:jli.dll
File size:2'463'232 bytes
SHA256 hash: da1b23ab25af799ed6c5db960337404c6a820022fd2bfe3e4c0c723f9e588573
MD5 hash: c3b99f0ebf0391a4ef446a06d555a423
MIME type:application/x-dosexec
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:31'344 bytes
SHA256 hash: 85fcf08d290c2f1778b74d44e4be32b3b834bf67e7784d0d539e7a6e3ef4116a
MD5 hash: e8a5929e5f797025e59176633252646a
MIME type:application/x-dosexec
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:31'352 bytes
SHA256 hash: ddd98a6b3200a7ee51a85f06ae380a0d2be76ccdf24dffab1f99c595a16dd4b2
MD5 hash: b365355962481d079b3d78915bd08db4
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
n/a  -.1/10
Confidence:
100%
Tags:
expired-cert microsoft_visual_cc packed signed
Threat name:
ByteCode-MSIL.Trojan.Zilla
Status:
Malicious
First seen:
2025-04-03 13:53:02 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery execution
Malware Config
Dropper Extraction:
https://app-updater1.app/api/getFile?fn=platon.hta
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Jupyter_infostealer
Author:CD_R0M_
Description:Rule for Jupyter Infostealer/Solarmarker malware from september 2021-December 2022
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip f1131dc6bbbfa8054b0f3d0c07fb220bb1eb613921ced4bbed909fd4a8b69238

(this sample)

  
Delivery method
Distributed via web download

Comments