MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed |
|---|---|
| SHA3-384 hash: | ba2224da632823d56b901cf1ff0d0228b4171bbbde0d8b2dcc0409022b385e17e827efad818a66caff4a885d0686c37a |
| SHA1 hash: | 97a73641431173f0239341a4d8ed4b5a534da2f5 |
| MD5 hash: | 3544426b23e38f543e1f20ea11de831b |
| humanhash: | mango-south-friend-quebec |
| File name: | DocumentFormatOpenXml.csproj |
| Download: | download sample |
| File size: | 9'256'933 bytes |
| First seen: | 2026-08-07 16:02:47 UTC |
| Last seen: | Never |
| File type: | unknown |
| MIME type: | text/xml |
| ssdeep | 1536:S51cozcDGLumsdMNOfBCMs3Iq1T+4gSBALAG2y/6ElEhYGCDw7TOKYHWZ5UUN9YH:h |
| TLSH | T10F96027B07C087BAF3D44BC4845A241E26F9E565B9213199AB7329FFBC2A9C7407C643 |
| TrID | 48.9% (.PROJ) MSBuild Project (84000/1/12) 25.0% (.CSPROJ) Visual Studio C# Project (43000/1/10) 23.0% (.TARGETS) MSBuild Targets (39500/1/9) 2.9% (.XML) Generic XML (ASCII) (5000/1) |
| Magika | txt |
| Reporter | |
| Tags: | Amatera AmateraStealer csproj EtherHiding lolbin MSBuild packer RenPyLoader |
Xorbit
Weaponised MSBuild carrier project. Between two [Emit-<guid>] markers it stores the stage-4 assembly as 3,054,080 comma-separated integers. The loader rebuilds it with table = bytes(range(256)) + <raw bytes of this .csproj>, then payload[i] = table[values[i]] - so values 0-255 are literal bytes and the ~16% above 255 are back-references into this file's own XML preamble. The payload is keyed to the exact bytes of this file, which is why the loader deletes it immediately after use. Reformatting the XML destroys the payload.Intelligence
File Origin
# of uploads :
1
# of downloads :
9
Origin country :
ROVendor Threat Intelligence
Verdict:
Unknown
Threat level:
2.5/10
Confidence:
100%
Score:
53%
Verdict:
Susipicious
File Type:
SCRIPT
Gathering data
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
DriveBy Activity
Score:
0.90
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
unknown f31df9170d3d70c2e3a84e56f1dabe093f19c79013a4d741cda3697ab2a93eed
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.