TF-1812049
high
📛 Threat Title
Unknown malware: SHA256 hash of a malware sample (payload) bbaf69f94449b05c868e6fe69a94ce9119c8d37dea6170047cad024a4c034c9e
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 75. First seen: 2026-05-14 03:12:29 UTC. Reporter: Lenny_3BO. Tags: AEZA, ClickFix, hollow-host, midie, sectoprat-shared-infra, signed-veritas, VDSINA.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
bbaf69f94449b05c868e6fe69a94ce9119c8d37dea6170047cad024a4c034c9e
IOC database
- Type
- hash_sha256
- Value
bbaf69f94449b05c868e6fe69a94ce9119c8d37dea6170047cad024a4c034c9e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SHA256 hash of a malware sample (payload) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 75. First seen: 2026-05-14 03:12:29 UTC. Reporter: Lenny_3BO. Tags: AEZA, ClickFix, hollow-host, midie, sectoprat-shared-infra, signed-veritas, VDSINA.
Remediations (10)
-
web:bazaar.abuse.ch
Using the form below, you can search for malware samples by a hash (MD5, SHA256 , SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database
-
web:github.com
The Flagged Hash .csv file is a meticulously curated collection of file hashes (MD5, SHA-1, SHA-256 , etc.) associated with malware , ransomware, and other cyber threats. This list consolidates information from reputable cybersecurity sources, ensuring a comprehensive tool for identifying and neutralizing potential threats.
-
web:github.com
Malware samples for analysis, researchers, anti-virus and system protection testing (1600+ Malware-samples !). - Pyran1/MalwareDatabase
-
web:hashes.com
Identify hash types Identify and detect unknown hashes using this tool. This page will tell you what type of hash a given string is. If you want to attempt to Decrypt them, click this link instead. Decrypt Hashes
-
web:inventivehq.com
Free hash lookup tool. Search MD5, SHA-1, SHA-256 hashes in breach databases to identify compromised passwords, malware , and file integrity.
-
web:ismalicious.com
Learn how cryptographic file hashes power malware identification, why SHA-256 dominates security tooling, and how to combine hash lookups with broader threat intelligence for fewer false positives.
-
web:talosintelligence.com
Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .
-
web:threatfox.abuse.ch
Using the form below, you can search for malware samples by a hash (MD5, SHA256 , SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database
-
web:virusvault.vercel.app
VirusVault Browse, search and analyze malware samples from around the world. Access a comprehensive database of security threats with detailed analysis.
-
web:www.virustotal.com
VirusTotal provides tools for inspecting files, domains, IPs, and URLs to detect malware and other threats.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.