MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fae42d2a7fb879f328cdbd7157de318bfe47134156f152cf2356e9652e732852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Sazoora


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: fae42d2a7fb879f328cdbd7157de318bfe47134156f152cf2356e9652e732852
SHA3-384 hash: baca307df230c37cdbe0395c7e715f14d6efe4746decddbcfd1541c31a71077d77490ffd0544e43988ca250d2e3ab3ee
SHA1 hash: 67cddbe5b7bf70c71e05f80b5bdc70a23dca0ab5
MD5 hash: 11b40f7a933bf15d2eaf184af96d62e3
humanhash: glucose-bravo-speaker-thirteen
File name:Windows_Update_Assistant (4).exe
Download: download sample
Signature Sazoora
File size:85'019'037 bytes
First seen:2026-07-26 11:38:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (589 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:0rziNx5qlpvenpSeA5MR8TIHzFV7w2rOs5FkDgRPn7:fx5qlEpHdTzbhis5357
TLSH T17D183376AA25027ACE854F7452B047710AFFBF716F7590BF99A0701E9E334879A30D22
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 8c32f0cccce86996 (1 x Sazoora)
Reporter JAMESWT_WT
Tags:exe Sazoora Windows-Update-Assistant

Intelligence


File Origin
# of uploads :
1
# of downloads :
277
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Searching for the window
Сreating synchronization primitives
Creating a file
Creating a process from a recently created file
Creating a window
Creating a file in the system32 directory
Deleting a recently created file
DNS request
Unauthorized injection to a recently created process
Searching for synchronization primitives
Connection attempt
Sending a custom TCP request
Loading a suspicious library
Creating a process with a hidden window
Creating a file in the %AppData% subdirectories
Launching a process
Moving a file to the %AppData% subdirectory
Launching a service
Running batch commands
Forced system process termination
Launching a tool to kill processes
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-26T09:46:00Z UTC
Last seen:
2026-07-26T09:55:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.Generic
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution persistence spyware stealer trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Drops file in System32 directory
Adds Run key to start application
Contacts third-party web service commonly abused for C2
Obfuscated Files or Information: Command Obfuscation
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
UAC bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments