MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fee1a26536687e67d0d18461a2ca2977475ebe453b124ef69e35d484e3ca2828. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: fee1a26536687e67d0d18461a2ca2977475ebe453b124ef69e35d484e3ca2828
SHA3-384 hash: 34626b81891d073fa53440c792c77519cf806767da50d37981b989eed9be37d89da84f12c487e09882739979d6b0c49e
SHA1 hash: f680c791138d5f89a5ae2a5021821cdb3985e162
MD5 hash: 8c38771d1d3c4a4e4a4c41dbf179fca7
humanhash: november-spring-kitten-spring
File name:z120260826_547281_6E9A319CD53AFD.img
Download: download sample
File size:2'064'384 bytes
First seen:2026-08-27 14:01:17 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:oV1McSAGWyV3PtxRS1dGaY6w4wPrALhAYvogQEKZm+jWodEE7C87ybQKDKh15/Y6:oUcSAGHPtxR2MrALVvt38AUi+0j
TLSH T116A59E27B75842E8D16AE27896878712E7F17449032297CB03E6966E2F277D16F3F310
TrID 88.4% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.1% (.ASSETS) Unity binary serialized Assets (generic) (2509/3/1)
Magika iso
Reporter FXOLabs
Tags:img

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
US US
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:vcruntime140_1.dll
File size:60'072 bytes
SHA256 hash: 1a1ca015a830a357ad5ec882845d732a60368b6c0d8247a009140cd518377f73
MD5 hash: 0bdae05fc660c889f1a3a6fd0d7ca3e4
MIME type:application/x-dosexec
File name:resmonitor.dll
File size:181'464 bytes
SHA256 hash: 9f185ed99336d159f552d85ac12e276874ef42c8fd4a05eacbe9da3f7b9f0520
MD5 hash: 8688688ab59154a5c379b01877ed351d
MIME type:application/x-dosexec
File name:20260826.547281.6E9A319CD53AFD.exe
File size:48'856 bytes
SHA256 hash: 4ba01b04681a5273facdd8b17e7b7b2246ee0eab6168c932946e7e96b9099e2d
MD5 hash: 0dcc1bacda98269a9f44a8777ea6e272
MIME type:application/x-dosexec
File name:vcruntime140.dll
File size:130'704 bytes
SHA256 hash: 98aea63f7c88d733504c08b165fd68a917e256f2cfaeaa742323ef6dddbbce29
MD5 hash: d59f36ddcc7460bf5bcd9fde274982bb
MIME type:application/x-dosexec
File name:core.dll
File size:683'736 bytes
SHA256 hash: 17987c47aeab610dec6364c869ab3ab4dac322782a041ff39b3272326b9ddd81
MD5 hash: 0b11f0e6306454dc56f0c9421011e8a5
MIME type:application/x-dosexec
File name:msvcp140.dll
File size:585'872 bytes
SHA256 hash: b5400f8454276f1adf944d8ba393866ca423603254baf88bca7dc4c1cf762116
MD5 hash: cdf7a0cc26ed6b4136ce69b74d8694ed
MIME type:application/x-dosexec
File name:service.dll
File size:306'496 bytes
SHA256 hash: af0f7afac3760cc02ce84b9786a9af57350528c7e21fcdbbfa1ad59a9e6e3b52
MD5 hash: 49e40c2655776eebc3932980bc790a58
MIME type:application/x-dosexec
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug microsoft_visual_cc overlay packed packed packed packer reconnaissance upx
Verdict:
Malicious
File Type:
iso
First seen:
2026-08-27T11:41:00Z UTC
Last seen:
2026-08-29T12:33:00Z UTC
Hits:
~1000
Threat name:
Win32.Trojan.DllHijack
Status:
Malicious
First seen:
2026-08-27 10:11:07 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

img fee1a26536687e67d0d18461a2ca2977475ebe453b124ef69e35d484e3ca2828

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments