🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b749e8cecc2af7322eac65aaf6aa76b0731f6e845e8a04af5585b90341481cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 6 File information Comments

SHA256 hash: 0b749e8cecc2af7322eac65aaf6aa76b0731f6e845e8a04af5585b90341481cf
SHA3-384 hash: 4890100272a557e7007f01daacf1c5c86078b19639ca6e0a5f1b9a264ca050f443e4661c09db4b3a9d0cf11a2e9709c5
SHA1 hash: ddc1f50344804dea4a72aa98b4e3ffc6559f9a4a
MD5 hash: 425ff3351eafc1d4bc5bd3e8fb78d012
humanhash: november-high-kansas-arizona
File name:0b749e8cecc2af7322eac65aaf6aa76b0731f6e845e8a04af5585b90341481cf.exe
Download: download sample
File size:2'303'758 bytes
First seen:2026-09-25 17:09:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (26 x ValleyRAT, 20 x OffLoader, 14 x Tofsee)
ssdeep 49152:DuI2h4QIb2k9I9wUGSDTuzlSjee3w6EugBqC2S:D5O4QIikWhGS/uzlSR3w6c
TLSH T166B5D03BA24F653DE42E163579F2A224443F7FA169124C1A96E0E44CEF354B42E3E787
TrID 63.8% (.EXE) Inno Setup installer (107240/4/30)
24.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.8% (.EXE) Win64 Executable (generic) (6522/11/2)
2.6% (.EXE) Win32 Executable (generic) (4504/4/1)
1.2% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon dc8e8aaab2b6eef4
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Suspicious activity
Analysis date:
2026-09-25 17:22:55 UTC
Tags:
delphi inno installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Unknown
File Type:
exe x32
First seen:
2026-09-27T04:05:00Z UTC
Last seen:
2026-09-27T04:30:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
32 / 100
Signature
Changes security center settings (notifications, updates, antivirus, firewall)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Reads the Security eventlog
Reads the System eventlog
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1978328 Sample: g5cHPpUxaB.exe Startdate: 25/09/2026 Architecture: WINDOWS Score: 32 51 Multi AV Scanner detection for submitted file 2->51 53 Joe Sandbox ML detected suspicious sample 2->53 8 VARQOO.RdpGuard.Service.exe 2 9 2->8         started        11 g5cHPpUxaB.exe 2 2->11         started        14 svchost.exe 2->14         started        16 5 other processes 2->16 process3 file4 55 Reads the Security eventlog 8->55 57 Reads the System eventlog 8->57 49 C:\Users\user\AppData\...\g5cHPpUxaB.tmp, PE32 11->49 dropped 18 g5cHPpUxaB.tmp 30 23 11->18         started        59 Changes security center settings (notifications, updates, antivirus, firewall) 14->59 21 MpCmdRun.exe 14->21         started        signatures5 process6 file7 41 C:\...\VARQOO.RdpGuard.Service.exe (copy), PE32 18->41 dropped 43 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 18->43 dropped 45 C:\Program Files\...\unins000.exe (copy), PE32 18->45 dropped 47 7 other files (none is malicious) 18->47 dropped 23 cmd.exe 1 18->23         started        25 sc.exe 1 18->25         started        27 VARQOO.RdpGuard.Manager.exe 2 18->27         started        29 conhost.exe 21->29         started        process8 process9 31 conhost.exe 23->31         started        33 fltMC.exe 1 23->33         started        35 sc.exe 1 23->35         started        39 5 other processes 23->39 37 conhost.exe 25->37         started       
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution installer persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Launches sc.exe
Checks installed software on the system
Creates new service(s)
Executes dropped EXE
Loads dropped DLL
Stops running service(s)
Unpacked files
SH256 hash:
0b749e8cecc2af7322eac65aaf6aa76b0731f6e845e8a04af5585b90341481cf
MD5 hash:
425ff3351eafc1d4bc5bd3e8fb78d012
SHA1 hash:
ddc1f50344804dea4a72aa98b4e3ffc6559f9a4a
SH256 hash:
424c921da78e91b78aa937ead7104e383d497f69fd0faf6d33b048350cbd397c
MD5 hash:
042c185ebdd8b6c38d5f1010258bd543
SHA1 hash:
16ad092c96d6df3cc2b92dc4922e2dac08565c73
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 0b749e8cecc2af7322eac65aaf6aa76b0731f6e845e8a04af5585b90341481cf

(this sample)

  
Delivery method
Distributed via web download

Comments