🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b9186fa35770dc3b4b121a35551d49c6d623c0cd8dafbc5bafbce2d5bdcd7f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: 0b9186fa35770dc3b4b121a35551d49c6d623c0cd8dafbc5bafbce2d5bdcd7f3
SHA3-384 hash: 0061a2457d6af50e14ebe03974fa7189cd65cf76d49665a8616989d4de02d096ea79baeed352be16bb851abbb27cbea3
SHA1 hash: cca8db27a784908e40544eda5f3d327e1bd1d088
MD5 hash: a5fd1dda9fd9746a6b21dcf2a6ee2160
humanhash: jig-snake-alaska-alabama
File name:V4L PR1V4T3.exe
Download: download sample
Signature SilentNet
File size:1'139'712 bytes
First seen:2026-09-08 08:22:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 73f461c771aef77ec43d53a0c54f0c8d (30 x SilentNet, 1 x CoinMiner)
ssdeep 12288:igbs/m0E54jwaFXGc8lEBBBHGBKq2IZwDYIvfqItNqdg:5bOVE5ifGPRZwRvf3fd
TLSH T16F357C83E7A385D8C116C9B5534BF137F9627C8E4B157197ABC41E633A67BA4E22CB00
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter burger
Tags:exe SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
V4L PR1V4T3.exe
Verdict:
Malicious activity
Analysis date:
2026-09-04 13:48:44 UTC
Tags:
silentnet stealer python gofile arch-exec arch-doc openssl tool auto generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Creating a file
Moving a recently created file
Deleting a recently created file
Creating a process from a recently created file
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
crypto downloader loader reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-28T04:09:00Z UTC
Last seen:
2026-09-07T05:55:00Z UTC
Hits:
~100
Result
Threat name:
EtherHiding
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates a thread in another existing process (thread injection)
Found direct / indirect Syscall (likely to bypass EDR)
Found suspicious ZIP file
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Writes many files with high entropy
Writes to foreign memory regions
Yara detected EtherHiding
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1969792 Sample: V4L PR1V4T3.exe Startdate: 08/09/2026 Architecture: WINDOWS Score: 100 78 www.python.org 2->78 80 thisisafalsepositive.st 2->80 82 7 other IPs or domains 2->82 98 Suricata IDS alerts for network traffic 2->98 100 Antivirus detection for URL or domain 2->100 102 Antivirus / Scanner detection for submitted sample 2->102 104 5 other signatures 2->104 9 V4L PR1V4T3.exe 4 2->9         started        signatures3 process4 dnsIp5 84 rpc-mainnet.matic.quiknode.pro 150.136.141.142, 443, 49730, 49761 ORACLE-BMC-31898-OracleCorporationUS United States 9->84 86 polygon-rpc.com 198.178.224.35, 443, 49729, 49760 LATITUDE-SH-LatitudeshUS United States 9->86 106 Found direct / indirect Syscall (likely to bypass EDR) 9->106 13 python.exe 9->13         started        16 python.exe 1111 9->16         started        20 python.exe 9->20         started        22 6 other processes 9->22 signatures6 process7 dnsIp8 48 C:\Users\user\AppData\Local\...\tmpz3gaq7jj, Zip 13->48 dropped 50 C:\Users\user\AppData\Local\...\tmpy4qp8ul6, Zip 13->50 dropped 52 C:\Users\user\AppData\Local\...\tmpjzh9k3do, Zip 13->52 dropped 58 513 other files (9 malicious) 13->58 dropped 24 conhost.exe 13->24         started        66 pypi.org 151.101.192.223, 443, 49744, 49750 FASTLY-FastlyIncUS Canada 16->66 68 151.101.64.223, 443, 49745, 49751 FASTLY-FastlyIncUS Canada 16->68 60 392 other files (none is malicious) 16->60 dropped 88 Writes many files with high entropy 16->88 26 conhost.exe 16->26         started        70 151.101.0.175, 443, 49767 FASTLY-FastlyIncUS Canada 20->70 54 C:\Users\user\AppData\...\tmp_f8obdg2v.zip, Zip 20->54 dropped 62 34 other files (1 malicious) 20->62 dropped 90 Tries to harvest and steal browser information (history, passwords, etc) 20->90 92 Writes to foreign memory regions 20->92 94 Allocates memory in foreign processes 20->94 96 Creates a thread in another existing process (thread injection) 20->96 28 python.exe 20->28         started        30 cmd.exe 20->30         started        32 chrome.exe 20->32         started        72 dualstack.python.map.fastly.net 151.101.0.223, 443, 49733 FASTLY-FastlyIncUS Canada 22->72 74 dualstack.c.ssl.global.fastly.net 151.101.192.175, 443, 49736 FASTLY-FastlyIncUS Canada 22->74 76 2 other IPs or domains 22->76 56 C:\Users\user\AppData\Local\...\python.exe, PE32+ 22->56 dropped 64 33 other files (2 malicious) 22->64 dropped 34 conhost.exe 22->34         started        36 conhost.exe 22->36         started        38 conhost.exe 22->38         started        40 3 other processes 22->40 file9 signatures10 process11 process12 42 conhost.exe 28->42         started        44 cmd.exe 28->44         started        46 conhost.exe 30->46         started       
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Convagent
Status:
Malicious
First seen:
2026-08-31 11:24:58 UTC
File Type:
PE+ (Exe)
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig defense_evasion discovery execution miner persistence privilege_escalation spyware stealer
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
cURL User-Agent
Browser Information Discovery
Event Triggered Execution: Netsh Helper DLL
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Modifies Windows Firewall
XMRig Miner payload
Family: xmrig
Unpacked files
SH256 hash:
0b9186fa35770dc3b4b121a35551d49c6d623c0cd8dafbc5bafbce2d5bdcd7f3
MD5 hash:
a5fd1dda9fd9746a6b21dcf2a6ee2160
SHA1 hash:
cca8db27a784908e40544eda5f3d327e1bd1d088
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments