🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d7abf4cfeabb9378134799d455bc6cd6b1ecf8182eaebdb2f265c31deb4d616. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 13


Intelligence 13 IOCs YARA 10 File information Comments

SHA256 hash: 0d7abf4cfeabb9378134799d455bc6cd6b1ecf8182eaebdb2f265c31deb4d616
SHA3-384 hash: b0db75c202b53562dfcf2f3ff8a67aa733473f6f1b1582d6858fa0233d313d2a7b28c6cd455fd4f9a6b0033dfd8122d2
SHA1 hash: ce5c450236bd4f20dfdae91884fd2ecff97ce3ff
MD5 hash: 330122a06ff07116214ee6e544a4da67
humanhash: hotel-fillet-india-solar
File name:0d7abf4cfeabb9378134799d455bc6cd6b1ecf8182eaebdb2f265c31deb4d616.exe
Download: download sample
File size:3'811'822 bytes
First seen:2026-09-24 13:03:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 573bb7b41bc641bd95c0f5eec13c233b (66 x GuLoader, 32 x AgentTesla, 31 x RemcosRAT)
ssdeep 98304:FHbqeBAq1toOr4onSgLKJCrJKL4fRxFiRy6xmPWS6+:F7qQ0onSwKJCrUL4Zx4TwPWm
TLSH T182062315A3A858F5E2779334CC924217E6B27C254B31979F23E1079A3E373A0AE3D761
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b3b3b371716b93b3 (25 x CryptOne, 12 x RemcosRAT, 7 x AsyncRAT)
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-24 14:48:28 UTC
Tags:
onyxc2 stealer auto-sch loader arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process with a hidden window
Creating a file
Creating a process from a recently created file
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Launching a service
Adding an exclusion to Microsoft Defender
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm crypto evasive expand expired-cert explorer fingerprint fingerprint installer installer keylogger lolbin microsoft_visual_cc mpcmdrun nsis overlay packed reconnaissance regedit
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-09-24T04:51:00Z UTC
Last seen:
2026-09-24T08:47:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Win32.Generic HEUR:Trojan.Win32.Agent.gen Trojan.Win32.Agent.xcfvgq BSS:Trojan.Win32.Generic Trojan.Win64.Reflo.sb Trojan.Win32.Agent.sb
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
68 / 100
Signature
Adds a directory exclusion to Windows Defender
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionality to steal saved passwords of Firefox
Drops executables to the windows directory (C:\Windows) and starts them
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for submitted file
Potential Privilege Escalation using Task Scheduler highest RunLevel
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal browser information (history, passwords, etc)
Uses known network protocols on non-standard ports
Uses schtasks.exe or at.exe to add and modify task schedules
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1977694 Sample: XiQQdmodVo.exe Startdate: 24/09/2026 Architecture: WINDOWS Score: 68 82 simplswop.io 2->82 94 Malicious sample detected (through community Yara rule) 2->94 96 Antivirus detection for URL or domain 2->96 98 Multi AV Scanner detection for submitted file 2->98 100 5 other signatures 2->100 10 XiQQdmodVo.exe 32 2->10         started        15 MicrosoftEdgeSecurity.exe 2->15         started        signatures3 process4 dnsIp5 84 45.225.135.164, 49714, 8081 RACKSPHEREHOSTINGSAPA Netherlands 10->84 66 C:\WindowsdgeUpdate\test.exe, PE32+ 10->66 dropped 68 C:\Users\user\Desktop\winrar-x64-710.exe, PE32+ 10->68 dropped 70 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 10->70 dropped 72 C:\Users\user\AppData\Local\...\INetC.dll, PE32 10->72 dropped 102 Bypasses PowerShell execution policy 10->102 104 Drops executables to the windows directory (C:\Windows) and starts them 10->104 106 Adds a directory exclusion to Windows Defender 10->106 17 test.exe 10->17         started        21 powershell.exe 23 10->21         started        23 powershell.exe 23 10->23         started        25 2 other processes 10->25 file6 signatures7 process8 file9 56 C:\Windows\...\MicrosoftEdgeSecurity.exe, PE32+ 17->56 dropped 88 Drops executables to the windows directory (C:\Windows) and starts them 17->88 27 MicrosoftEdgeSecurity.exe 17->27         started        32 cmd.exe 17->32         started        34 cmd.exe 17->34         started        90 Found many strings related to Crypto-Wallets (likely being stolen) 21->90 92 Loading BitLocker PowerShell Module 21->92 36 conhost.exe 21->36         started        38 conhost.exe 23->38         started        58 C:\Program Files\WinRAR\Zip32.SFX, PE32 25->58 dropped 60 C:\Program Files\WinRAR\Zip.SFX, PE32+ 25->60 dropped 62 C:\Program Files\WinRAR\WinRAR.exe, PE32+ 25->62 dropped 64 11 other files (none is malicious) 25->64 dropped 40 Uninstall.exe 134 13 25->40         started        42 conhost.exe 25->42         started        signatures10 process11 dnsIp12 86 simplswop.io 172.67.133.231, 443, 49715 CLOUDFLARENET-CloudflareIncUS Canada 27->86 74 C:\Users\user\AppData\...74YMMPCEIMA.jpg, ASCII 27->74 dropped 76 C:\Users\user\AppData\...\BJZFPPWAPT.jpg, ASCII 27->76 dropped 78 C:\Users\user\AppData\...\QCOILOQIKC.png, ASCII 27->78 dropped 80 C:\Users\user\AppData\...FOYFBOLXA.docx, ASCII 27->80 dropped 108 Contains functionality to steal saved passwords of Firefox 27->108 110 Found many strings related to Crypto-Wallets (likely being stolen) 27->110 112 Contains functionality to inject threads in other processes 27->112 118 4 other signatures 27->118 114 Uses schtasks.exe or at.exe to add and modify task schedules 32->114 116 Potential Privilege Escalation using Task Scheduler highest RunLevel 32->116 44 conhost.exe 32->44         started        46 schtasks.exe 32->46         started        48 conhost.exe 34->48         started        50 timeout.exe 34->50         started        52 MpCmdRun.exe 36->52         started        file13 signatures14 process15 process16 54 conhost.exe 52->54         started       
Verdict:
Malware
YARA:
6 match(es)
Tags:
Archive 7z non extractible (chiffrée, corrompue ou vide) DeObfuscated Executable NSIS Installer PDB Path PE (Portable Executable) PE File Layout PowerShell T1027 T1059.001 Win 32 Exe x86
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution persistence privilege_escalation spyware stealer trojan
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Checks installed software on the system
Checks whether UAC is enabled
Drops desktop.ini file(s)
Network Share Discovery
Checks computer location settings
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Modifies system executable filetype association
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Unpacked files
SH256 hash:
0d7abf4cfeabb9378134799d455bc6cd6b1ecf8182eaebdb2f265c31deb4d616
MD5 hash:
330122a06ff07116214ee6e544a4da67
SHA1 hash:
ce5c450236bd4f20dfdae91884fd2ecff97ce3ff
SH256 hash:
0b96d0ec2ccc666583cd850e843eeb9fa318085104063146b1dd66602de26049
MD5 hash:
a1540885b2dd0255a67794ae867b0fee
SHA1 hash:
5de6209bb0dbe01c993036d5c982c27bed1c9456
SH256 hash:
85e03805f90f72257dd41bfdaa186237218bbb0ec410ad3b6576a88ea11dccb9
MD5 hash:
40d7eca32b2f4d29db98715dd45bfac5
SHA1 hash:
124df3f617f562e46095776454e1c0c7bb791cc7
SH256 hash:
3a101fa91d4e8831dfb748a1e345ab74fd4a551e64254710bdf53972ba9b473c
MD5 hash:
c953dd0aab774f1446fcd63fa7c5f613
SHA1 hash:
6b7e1ef30b3ce2b353d310a8c99111c01e1f752e
SH256 hash:
ccc18d118969a42508f5c71999759421f3c308e85155c817693dbaf31dadff6f
MD5 hash:
e64c869a7d298647e75c0ef87f189125
SHA1 hash:
11f79a0ed6dffff99820412a53947872a40a8f3d
SH256 hash:
1656fc44d7d28ecee5013d4fe74d376a945bc03fa788cf9e2d17a0a53daf708d
MD5 hash:
46175fed2691f8b5d363350e4a703ae0
SHA1 hash:
236e6d3f582c248c0bca0b21de47f501b38add13
SH256 hash:
33698e40caf37aae399c3d9c7adcc7433d1fde085c9200b21f12bf34bf2565fe
MD5 hash:
b39eb490b8217b48a709202b4a574e51
SHA1 hash:
2eb995dd4c188b9aaa3e2e0c648f46d606d2bfbd
SH256 hash:
44b8cde375358c1c139c547bf9e13575a48494d92ff685175292418f851c931a
MD5 hash:
032032c717b371a6eb363e32204039f5
SHA1 hash:
0862edee5b0e939bba2d2c46b3c45a9926e2d101
SH256 hash:
5ed96affb99fa93dc4e9a553d561fa6c5719cf10241307c927c111d2fc1b2200
MD5 hash:
b80947fceea9a472758e89231619eb2f
SHA1 hash:
e24948a753223ec8f7ab62be5c1f42b299bb57d8
SH256 hash:
8b080f95bbdd6b6cdafe28d8e6de17f38354b06c5904b9cdcdd15376341ce333
MD5 hash:
b292a6d3cc758b590766f60a132b9255
SHA1 hash:
3e7ba71b8342940461ec75312220a1f2afe612e7
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NSIS
Author:kevoreilly
Description:NSIS Integrity Check function
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 0d7abf4cfeabb9378134799d455bc6cd6b1ecf8182eaebdb2f265c31deb4d616

(this sample)

  
Delivery method
Distributed via web download

Comments