🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



EpsilonStealer


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f
SHA3-384 hash: 27390c29dd2fe6fcb9587909a731a0201cc0f4232b35c5dc55959d68a53800d8ed24b7f7a3bfd97df4c93518e4ea1d26
SHA1 hash: fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423
MD5 hash: ab604354f690db061319959aec4073a2
humanhash: louisiana-georgia-music-lemon
File name:winhost.exe
Download: download sample
Signature EpsilonStealer
File size:84'625'707 bytes
First seen:2026-09-25 10:16:40 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (593 x GuLoader, 130 x RemcosRAT, 85 x EpsilonStealer)
ssdeep 1572864:9t9IKPM2xNA5uqoRWYnGvyUk/d5pHX9M6l4g3XLx+orcCta9mYl+eg1+fgf4dA7:9UKPNAgqoRWU/d5p3Nl4g3b9rja9mQ+X
TLSH T19708332EA171C704C46D02F60B621993D3ADBAAF8FA248075F5ABBC17E4D14951FF31A
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter smica83
Tags:EpsilonStealer exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
310
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-25 10:20:13 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Searching for the window
Launching a service
Сreating synchronization primitives
Creating a process from a recently created file
Creating a window
Running batch commands
Creating a process with a hidden window
Launching a process
Creating a file
Unauthorized injection to a recently created process
Searching for synchronization primitives
Loading a suspicious library
Moving a file to the %temp% subdirectory
DNS request
Creating a file in the %AppData% subdirectories
Connection attempt
Sending a custom TCP request
Adding an access-denied ACE
Deleting a recently created file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug bash crypto installer installer lolbin microsoft_visual_cc nsis reconnaissance
Verdict:
Adware
File Type:
exe x32
First seen:
2026-09-24T21:32:00Z UTC
Last seen:
2026-09-26T22:07:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Creates processes via WMI
Encrypted powershell cmdline option found
Found suspicious powershell code related to unpacking or dynamic code loading
Powershell connects to network
Powershell drops PE file
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive system registry key value via command line tool
Queries the machine ID of the display
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: PowerShell Base64 Encoded WMI Classes
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Sigma detected: Suspicious PowerShell Invocations - Generic - PowerShell Module
Suspicious powershell command line found
Tries to access browser extension known for cryptocurrency wallets
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1978137 Sample: winhost.exe Startdate: 25/09/2026 Architecture: WINDOWS Score: 100 79 surround-tough-method-zinc.trycloudflare.com 2->79 81 williams-angels-basically-until.trycloudflare.com 2->81 83 3 other IPs or domains 2->83 97 Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet 2->97 99 Sigma detected: Suspicious PowerShell Encoded Command Patterns 2->99 101 Sigma detected: Base64 Encoded PowerShell Command Detected 2->101 103 4 other signatures 2->103 11 winhost.exe 672 2->11         started        14 explorer.exe 2->14 injected signatures3 process4 file5 67 C:\Users\user\AppData\Local\...\winhost.exe, PE32+ 11->67 dropped 69 C:\Users\user\AppData\Local\...\nsis7z.dll, PE32 11->69 dropped 71 C:\Users\user\AppData\Local\...\System.dll, PE32 11->71 dropped 73 23 other files (none is malicious) 11->73 dropped 16 winhost.exe 70 11->16         started        process6 dnsIp7 75 ipinfo.io 34.117.59.81, 443, 49724 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 16->75 77 williams-angels-basically-until.trycloudflare.com 104.16.230.132, 443, 49725, 49726 CLOUDFLARENET-CloudflareIncUS Canada 16->77 87 Suspicious powershell command line found 16->87 89 Uses cmd line tools excessively to alter registry or file data 16->89 91 Encrypted powershell cmdline option found 16->91 93 4 other signatures 16->93 20 powershell.exe 16->20         started        23 powershell.exe 16->23         started        25 cmd.exe 16->25         started        27 37 other processes 16->27 signatures8 process9 signatures10 105 Suspicious powershell command line found 20->105 107 Encrypted powershell cmdline option found 20->107 109 Found suspicious powershell code related to unpacking or dynamic code loading 20->109 117 3 other signatures 20->117 29 conhost.exe 20->29         started        31 powershell.exe 23->31         started        36 conhost.exe 23->36         started        111 Uses cmd line tools excessively to alter registry or file data 25->111 113 Queries sensitive system registry key value via command line tool 25->113 38 conhost.exe 25->38         started        40 reg.exe 25->40         started        115 Queries the machine ID of the display 27->115 42 csc.exe 27->42         started        44 conhost.exe 27->44         started        46 chcp.com 27->46         started        48 35 other processes 27->48 process11 dnsIp12 85 surround-tough-method-zinc.trycloudflare.com 104.16.231.132, 443, 49730, 49731 CLOUDFLARENET-CloudflareIncUS Canada 31->85 59 C:\Users\user\AppData\Local\...\tmp33AE.tmp, PE32+ 31->59 dropped 61 C:\Users\user\AppData\...\mnnjkoh1.cmdline, Unicode 31->61 dropped 95 Powershell connects to network 31->95 50 csc.exe 31->50         started        53 conhost.exe 31->53         started        63 C:\Users\user\AppData\Local\...\nv1gswp3.dll, PE32 42->63 dropped 55 cvtres.exe 42->55         started        file13 signatures14 process15 file16 65 C:\Users\user\AppData\Local\...\mnnjkoh1.dll, PE32 50->65 dropped 57 cvtres.exe 50->57         started        process17
Gathering data
Result
Malware family:
epsilon
Score:
  10/10
Tags:
family:donutloader family:epsilon antivm defense_evasion discovery execution linux loader persistence spyware stealer
Behaviour
Checks processor information in registry
Kills process with taskkill
Modifies registry key
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Hide Artifacts: Ignore Process Interrupts
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Detects DonutLoader
Family: DonutLoader
Family: Epsilon Stealer
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments