MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed
SHA3-384 hash: ba2224da632823d56b901cf1ff0d0228b4171bbbde0d8b2dcc0409022b385e17e827efad818a66caff4a885d0686c37a
SHA1 hash: 97a73641431173f0239341a4d8ed4b5a534da2f5
MD5 hash: 3544426b23e38f543e1f20ea11de831b
humanhash: mango-south-friend-quebec
File name:DocumentFormatOpenXml.csproj
Download: download sample
File size:9'256'933 bytes
First seen:2026-08-07 16:02:47 UTC
Last seen:Never
File type:unknown
MIME type:text/xml
ssdeep 1536:S51cozcDGLumsdMNOfBCMs3Iq1T+4gSBALAG2y/6ElEhYGCDw7TOKYHWZ5UUN9YH:h
TLSH T10F96027B07C087BAF3D44BC4845A241E26F9E565B9213199AB7329FFBC2A9C7407C643
TrID 48.9% (.PROJ) MSBuild Project (84000/1/12)
25.0% (.CSPROJ) Visual Studio C# Project (43000/1/10)
23.0% (.TARGETS) MSBuild Targets (39500/1/9)
2.9% (.XML) Generic XML (ASCII) (5000/1)
Magika txt
Reporter Xorbit
Tags:Amatera AmateraStealer csproj EtherHiding lolbin MSBuild packer RenPyLoader


Avatar
Xorbit
Weaponised MSBuild carrier project. Between two [Emit-<guid>] markers it stores the stage-4 assembly as 3,054,080 comma-separated integers. The loader rebuilds it with table = bytes(range(256)) + <raw bytes of this .csproj>, then payload[i] = table[values[i]] - so values 0-255 are literal bytes and the ~16% above 255 are back-references into this file's own XML preamble. The payload is keyed to the exact bytes of this file, which is why the loader deletes it immediately after use. Reformatting the XML destroys the payload.

Intelligence


File Origin
# of uploads :
1
# of downloads :
9
Origin country :
RO RO
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

unknown f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed

(this sample)

Comments