🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d27238cf157798b37db120effb4db2efd1d7061629a64f421d986d0bbae9062. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0d27238cf157798b37db120effb4db2efd1d7061629a64f421d986d0bbae9062
SHA3-384 hash: 1a65dd4a535c1c6c54417f6d57236200e414b57289eaa2179cc82a18b1fed70dc3c2b3a2dd702842da0c08e0ebf6be46
SHA1 hash: dc497c85ad13879eddaa3fc688aabde2f11e7c0d
MD5 hash: b36d140a2f395258f5bac01e31ef76ce
humanhash: speaker-foxtrot-network-floor
File name:ExternalMM.exe
Download: download sample
File size:116'966'836 bytes
First seen:2026-09-19 19:51:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9eba512b03d8cac8a6c4424e25e9f06e (7 x FrostStealer, 2 x MythStealer, 1 x CoinMiner)
ssdeep 1572864:1Pp36F/iKRzwo0EL9uXpXFxAI/MZqNrGZVOc4XIoC3MnluZQrZx:1PpIlwheuXpX/z/5NivOcC7hlTrX
TLSH T1DA48F01663E111AAD577D178C7AB6203EB72B40713308BDB329C43652F73AE45E7AB60
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon f89efcf8f971f2e0 (10 x NodeLoader, 9 x FixStealer, 6 x Amadey)
Reporter Anonymous
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
176
Origin country :
RO RO
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Running batch commands
Creating a process with a hidden window
Launching a process
Creating a window
Changing a file
Launching a service
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-16T16:32:00Z UTC
Last seen:
2026-09-21T18:04:00Z UTC
Hits:
~1000
Detections:
Trojan.Win32.Agent.sb
Gathering data
Threat name:
Win64.Malware.Generic
Status:
Suspicious
First seen:
2026-09-19 19:52:52 UTC
File Type:
PE+ (Exe)
Extracted files:
14
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution persistence
Behaviour
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Executes a command shell one-liner
Checks for VirtualBox DLLs, possible anti-VM trick
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments