MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f92d9dccd7472d97d292c1949b331866e03c6d56bed507c92f2b46c9a66939fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f92d9dccd7472d97d292c1949b331866e03c6d56bed507c92f2b46c9a66939fb
SHA3-384 hash: fc8f48ee2a6013af21f85aa9e737229003e66f3f323aedd85b1ec3c4e1e44c77f2720eb2023ccda9a713a9edfb705fa8
SHA1 hash: a91fda0e9ed49e55d121ffd22e91a13dfad7cea0
MD5 hash: c8c4df8f6d394fb3911e75d491b6c564
humanhash: pip-seventeen-fanta-massachusetts
File name:B C document.rar
Download: download sample
File size:9'372 bytes
First seen:2026-06-29 15:58:06 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 192:5xqzU8y7TCvrHWHntWaxMRCDID7BCb3bOIJXRU87H6AeoFWE+Dxx:5xCATCCJeUDC1C/OI5cAeE2xx
TLSH T14112AF10B466C5EFD82EA6C7110EA770CEA13AE9174098D28B9938B77D21BC3F5512D1
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter JAMESWT_WT
Tags:kzaa-co-za rar Spam-ITA xambby--tourtrade-shop

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
infosteal shell sage
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated Obfuscated Rar Archive T1059.005 VBScript WScript.Network
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments