🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f66fe201289db260631146fdc8f457622ea25fdb937e63be6358d763a9d827b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PavinLoader


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: f66fe201289db260631146fdc8f457622ea25fdb937e63be6358d763a9d827b2
SHA3-384 hash: 9fda5d4ddb96d6f9036385029ef291c4e67d5cbd05bda793518022d1fba6590d145b5983c0b2918bafff0e9ceb28e5ce
SHA1 hash: 421378f20c48a124a5bd6319f0131a9e5b808573
MD5 hash: 5a8b7981a563cc4060183ed53602f5be
humanhash: butter-saturn-east-johnny
File name:payload_decrypted.zip
Download: download sample
Signature PavinLoader
File size:18'297'531 bytes
First seen:2026-09-04 10:26:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:vnipQVgS2BEI5RwUVrVG62DgMbINL3FRyX:vniUpKRmgMcNL3v8
TLSH T1FD071F35038147A6F2CC6BC0446B296D22B9F66639942384FF737BBEDC1AAC79874147
Magika zip
Reporter aachum
Tags:dropped-by-RenPyLoader fipromwie-cfd PavinLoader zip


Avatar
iamaachum
https://cloud-file-2xlb.vvm4xwsy9.buzz/

PavinLoader IOCs:
https://fipromwie.cfd/HGFiv/get/DesightResun.js
https://fipromwie.cfd/HGFiv/file/oo1F0SfoR5Iv5ISyWHyX5H/DesightResun.js
https://fipromwie.cfd/HGFiv/event

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
ES ES
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:Directory.Build.props
File size:74'260 bytes
SHA256 hash: 07b227b4e3bb211472ee6b2c88e78d8743d1d054e5a053584dfb2bbb9b05ec5a
MD5 hash: e2a108baf817cc0a4b0e1ac29846cdd9
MIME type:text/xml
Signature PavinLoader
File name:Common.targets
File size:1'072'632 bytes
SHA256 hash: 31ff1dcc9700b3bf25073531e0de7e7a403d858b9f39e04c51a929401678c5a9
MD5 hash: c4181d5b39f862e53e5316f6647aa4da
MIME type:text/xml
Signature PavinLoader
File name:Nancy.csproj
File size:16'450'897 bytes
SHA256 hash: ab7ce9e0ec804439e221229092abd0a362804d8bb80a2a9d0d73e61f6c3abc85
MD5 hash: d579e898f1dde86459b52f399b91682d
MIME type:text/xml
Signature PavinLoader
File name:Nancy.csproj.user
File size:697'666 bytes
SHA256 hash: cded59a65079b8e1c602f5c9cfa84da1f2a43891c23bc4d2022b5ca7c9dd9eab
MD5 hash: 8cb7c948ea486eec7f78c842677a91b3
MIME type:text/xml
Signature PavinLoader
File name:XYYYFJyVf.cmd
File size:1'520 bytes
SHA256 hash: 002b0f4cbf476eb34367529e53420103ee337600044da399e4bf9f0e01c7d6a1
MD5 hash: 3505c853cf78aab96451bd2bf413b1a2
MIME type:text/x-msdos-batch
Signature PavinLoader
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-04 10:27:29 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
5 of 36 (13.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery execution
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_PatchWork_BADNEWS_20211105
Description:Detects PatchWork Group RTF or BADNEWS
Rule name:NET
Author:malware-lu
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PavinLoader

zip f66fe201289db260631146fdc8f457622ea25fdb937e63be6358d763a9d827b2

(this sample)

  
Delivery method
Distributed via web download

Comments