MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9
SHA3-384 hash: bf87c256d1fe3831132a6598a8e89a2c157dd2833e44aec08317021a8f732d3bf288fdd232357a49edee1366fca29561
SHA1 hash: 27a6b15ce77efe3ceec91793ac3d9ab8c544b46d
MD5 hash: 141b70024fd6cb2b6fec4c0d2d37622b
humanhash: quebec-carolina-yellow-one
File name:upd3c8ff0e8e6.exe
Download: download sample
File size:106'496 bytes
First seen:2026-07-17 18:07:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ff3a6433f70fee894efb5cbb88e2d101
ssdeep 1536:PM7vtr/Uq+QtYX0LnWH3+4Xl7ObogVEPQYl2T0mj33:UTtr/H+QtYX0Wu4X1KCPQYnmj33
TLSH T183A33803A2D481FDD58AC378C78B5936E7E2B4CA0936F39E1BD40D607A63B645F2A741
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter NoNameABC
Tags:exe payload PE Stage2 Ukraine


Avatar
NoNameABC
Stage 2 intermediate PE payload. Part of a multi-stage phishing campaign targeting Ukrainian businesses (Lure: Verkhovna Rada of Ukraine).

1. ROLE IN EXECUTION CHAIN:
This payload is part of a "Russian doll" execution cascade. It is downloaded/executed by the initial JS loader. Its specific role is to act as a stepping stone (Stage 2) to load the next intermediate executable (e.g., "67sSMhFVwqb.exe" dropped into the Temp folder). Communicates with C2: 31.76.252.31.

2. DOWNSTREAM PERSISTENCE:
The subsequent Stage-3 executable ("67sSMhFVwqb.exe") is responsible for dropping the final persistence payload into the Startup directory (often named "getconfigurator.exe").
CRITICAL NOTE: The downstream payloads exhibit polymorphic behavior (hashes change per execution).

3. VISUAL ANALYSIS:
- Attack Graph & Execution Flow: https://ibb.co/XZz1VmvT

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
UA UA
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Vymoga_VR_Registry_Audit_Forma_3_Signed_17_07_2026.js
Verdict:
Malicious activity
Analysis date:
2026-07-17 05:49:22 UTC
Tags:
loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-17 12:18:03 UTC
File Type:
PE+ (Exe)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
002285d2ef0ec7e6ede744fe739022507ac89da3feffd2a231ac0c31eb5204b9
MD5 hash:
141b70024fd6cb2b6fec4c0d2d37622b
SHA1 hash:
27a6b15ce77efe3ceec91793ac3d9ab8c544b46d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments