TF-1832449
high
📛 Threat Title
Unknown malware: SHA256 hash of a malware sample (payload) a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-06-15 19:40:18 UTC. Reporter: Colwilson. Tags: Downloader, iran, mois, MuddyWater, stagecomp.
Remediations (10)
-
web:bazaar.abuse.ch
Using the form below, you can search for malware samples by a hash (MD5, SHA256 , SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database
-
web:cipherssecurity.com
What it does When you encounter an unknown executable, the fastest triage step is hash reputation: compute its cryptographic fingerprint and check threat-intel feeds for prior submissions. Our checker queries MalwareBazaar (abuse.ch's curated malicious- sample database) and VirusTotal, returning the aggregated verdict plus per-source details.
-
web:inventivehq.com
File Hash Checker & Malware Hash Lookup Drag in a file to hash it locally (SHA-256/SHA-1, nothing uploaded), or paste MD5/SHA-1/SHA-256 hashes — single or in bulk — and check them against known malware with VirusTotal & MalwareBazaar deep-links.
-
web:ismalicious.com
Database of known malware file hashes. MD5, SHA1, and SHA256 hashes with malware family classification. Updated daily from sandbox analysis and vendor feeds.
-
web:talosintelligence.com
Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .
-
web:threatfox.abuse.ch
Using the form below, you can search for malware samples by a hash (MD5, SHA256 , SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database
-
web:www.hybrid-analysis.com
This is a free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology.
-
web:www.malshare.com
The MalShare Project is a community driven public malware repository that works to provide free access to malware samples and tooling to the infomation security community.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal provides tools for inspecting files, domains, IPs, and URLs to detect malware and other threats.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
IOC database
- Type
- hash_sha256
- Value
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- SHA256 hash of a malware sample (payload) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-06-15 17:22:54 UTC. Reporter: Colwilson. Tags: Downloader, iran, mois, MuddyWater, stagecomp.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.