MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f192d93e7a185acc5ae5968434de7adbe0ea8dcd6dd1a98b5fb3264e90e3ab65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: f192d93e7a185acc5ae5968434de7adbe0ea8dcd6dd1a98b5fb3264e90e3ab65
SHA3-384 hash: ba971a517056b71a80f2fa3ea9b2c0f4df9d39c2c2bb9fb3c876f361fdbe99bae97331bb1cbc29a66897b02a98af248d
SHA1 hash: 18f0683236478de32232463e08027293f83ab497
MD5 hash: 543099f3fb9f71758cef6282b096d074
humanhash: kentucky-undress-steak-echo
File name:stage2_decrypted.zip
Download: download sample
File size:10'682'761 bytes
First seen:2026-08-05 18:47:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:FXMQLeZnqZ89Z89ZOXubXvUv0x/Iv5lIOmODuuo4mnpKD83joav0JzytDBq0x5+q:FIgbXvUdlIU2Q83jojJzytDc0J
TLSH T1ECB6F17A0790437AF3D847C4885B345E36F4F556BAA53059A73369EFBC2A9CB8038643
Magika zip
Reporter Anonymous
Tags:FakeTrainer flingtrainer lolbin MOTW-bypass pingtrack.click PPI


Avatar
Anonymous
Fake "FLiNG Trainer" game trainer. Downloaded 2026-08-05 from flingtrainer.us (typosquat of the legitimate flingtrainer.com) through a pay-per-install redirect chain on fya34z.site; file origin https://44f2d0879231e84c10cd.192169467.com/aa497f58d83a96e2f6e233492b06b2 . Delivered inside Archive.zip (824,323,824 bytes, SHA256 9b20839b0b95de7cb87eec223e60e5cd85cafd59e93739895a29fe8f07aeafdb) which masquerades as a Ren'Py visual novel and is padded with a 339,738,624-byte all-NULL member stored uncompressed (ZIP method 0) to exceed AV scan-size and sandbox upload limits. CHAIN: script.rpyc inside libwin64.rpa executes at Ren'Py engine init -> anti-sandbox checks (bundled sys_config package) -> decrypts config .pez (base64 then XOR with ASCII key "81034149cd6f48c8821340204f92766e") -> XOR-decrypts W1nZshy8Yxf5.By with ASCII key "75ejCl9jARHB" into a ZIP of MSBuild project files named after the unrelated OSS project zxing -> drops them to %TEMP%\tmp-<5 digits>-<12 alnum>\ and writes NTFS ADS :Zone.Identifier "ZoneId=0" to strip Mark-of-the-Web -> launched via conhost.exe --headless and forfiles.exe /c "cmd /c call @path" so that Microsoft-signed MSBuild.exe v4.0.30319 reconstructs a ~3MB .NET PE from decimal values held in MSBuild property groups and runs it in memory only. No unsigned executable is ever written to disk. MSBuild runs with an emptied command line. C2: https://<host-MAC-as-12-hex>.pingtrack.click/?id=<obf>&data[hash]=<victim> (fragments XORed with key "cLkY_x9"); the host MAC address is used as the beacon subdomain. Also contacts ipinfo.io for IP reconnaissance. Campaign pb_s=B_BB1_eb12_h5_67, affiliate tag=7Cbm8dH5:C1, offer id=968. THIS FILE: stage 2 after XOR decryption: the MSBuild fileless loader bundle

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
JP JP
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:EuzmiXGXt.cmd
File size:1'149 bytes
SHA256 hash: 8829dfbe098cec1ed37102a7c5f374b8aba5f6618f6fbeedeb8bed1fe7428c5c
MD5 hash: d3daa0a1348daf121a3fa73a5bb7f197
MIME type:text/x-msdos-batch
File name:Zxing.targets
File size:683'200 bytes
SHA256 hash: a264c2599501baaa8f29664268de47d8c0e14533f9d4a620192936dc7090b1db
MD5 hash: 58d8e8037f12e9a0b62c625b04daa3a2
MIME type:text/xml
File name:Zxing.Build.props
File size:13'464 bytes
SHA256 hash: d3cf6844b189af4d0608a0ef30ad22632c806fa5a1ffb2f6257d88c256769b9e
MD5 hash: 5c10b397903983a319a8c2a5670ffec2
MIME type:text/xml
File name:Zxing.csproj
File size:9'559'191 bytes
SHA256 hash: fb752774764f8d8e22bba837fd4b74e0f8e20bb81c1c39a65455b0178ee54abb
MD5 hash: 4cacd963a7f5b344b4ba8f3503cd5fbc
MIME type:text/xml
File name:Zxing.csproj.user
File size:425'211 bytes
SHA256 hash: e8665397d6f5f3eca4b6b6ee28bcfe02a2677a9ed78ee06f7960aabd49f5f41a
MD5 hash: 4ae43df55462c37cf0a9ef0a50b05aeb
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
cmd conhost lolbin msbuild
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-05 18:56:33 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
4 of 36 (11.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery execution
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
Suspicious use of NtSetInformationThreadHideFromDebugger
Looks up external IP address via web service
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_PatchWork_BADNEWS_20211105
Description:Detects PatchWork Group RTF or BADNEWS
Rule name:NET
Author:malware-lu
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip f192d93e7a185acc5ae5968434de7adbe0ea8dcd6dd1a98b5fb3264e90e3ab65

(this sample)

  
Delivery method
Distributed via web download

Comments