MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | 002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9 |
|---|---|
| SHA3-384 hash: | bf87c256d1fe3831132a6598a8e89a2c157dd2833e44aec08317021a8f732d3bf288fdd232357a49edee1366fca29561 |
| SHA1 hash: | 27a6b15ce77efe3ceec91793ac3d9ab8c544b46d |
| MD5 hash: | 141b70024fd6cb2b6fec4c0d2d37622b |
| humanhash: | quebec-carolina-yellow-one |
| File name: | upd3c8ff0e8e6.exe |
| Download: | download sample |
| File size: | 106'496 bytes |
| First seen: | 2026-07-17 18:07:56 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | ff3a6433f70fee894efb5cbb88e2d101 |
| ssdeep | 1536:PM7vtr/Uq+QtYX0LnWH3+4Xl7ObogVEPQYl2T0mj33:UTtr/H+QtYX0Wu4X1KCPQYnmj33 |
| TLSH | T183A33803A2D481FDD58AC378C78B5936E7E2B4CA0936F39E1BD40D607A63B645F2A741 |
| TrID | 33.1% (.EXE) Win64 Executable (generic) (6522/11/2) 25.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 10.4% (.ICL) Windows Icons Library (generic) (2059/9) 10.3% (.EXE) OS/2 Executable (generic) (2029/13) 10.1% (.EXE) Generic Win/DOS Executable (2002/3) |
| Magika | pebin |
| Reporter | |
| Tags: | exe payload PE Stage2 Ukraine |
NoNameABC
Stage 2 intermediate PE payload. Part of a multi-stage phishing campaign targeting Ukrainian businesses (Lure: Verkhovna Rada of Ukraine).1. ROLE IN EXECUTION CHAIN:
This payload is part of a "Russian doll" execution cascade. It is downloaded/executed by the initial JS loader. Its specific role is to act as a stepping stone (Stage 2) to load the next intermediate executable (e.g., "67sSMhFVwqb.exe" dropped into the Temp folder). Communicates with C2: 31.76.252.31.
2. DOWNSTREAM PERSISTENCE:
The subsequent Stage-3 executable ("67sSMhFVwqb.exe") is responsible for dropping the final persistence payload into the Startup directory (often named "getconfigurator.exe").
CRITICAL NOTE: The downstream payloads exhibit polymorphic behavior (hashes change per execution).
3. VISUAL ANALYSIS:
- Attack Graph & Execution Flow: https://ibb.co/XZz1VmvT
Intelligence
File Origin
# of uploads :
1
# of downloads :
140
Origin country :
UAVendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Vymoga_VR_Registry_Audit_Forma_3_Signed_17_07_2026.js
Verdict:
Malicious activity
Analysis date:
2026-07-17 05:49:22 UTC
Tags:
loader
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Verdict:
Clean
Score:
99.9%
Tags:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Connection attempt
Verdict:
Unknown
Threat level:
2.5/10
Confidence:
100%
Tags:
adaptive-context
Verdict:
Suspicious
Labled as:
Win64/Agent.KEY trojan
Verdict:
Unknown
File Type:
exe x64
Verdict:
Unknown
Score:
71%
Verdict:
Malware
File Type:
PE
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-17 12:18:03 UTC
File Type:
PE+ (Exe)
AV detection:
6 of 24 (25.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Unpacked files
SH256 hash:
002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9
MD5 hash:
141b70024fd6cb2b6fec4c0d2d37622b
SHA1 hash:
27a6b15ce77efe3ceec91793ac3d9ab8c544b46d
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
exe 002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9
(this sample)
Delivery method
Other
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.