🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12fc543c0e6dfc4b1542117b68bc5a8896e019de213633f65caf797c93a063e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 13 File information Comments

SHA256 hash: 12fc543c0e6dfc4b1542117b68bc5a8896e019de213633f65caf797c93a063e9
SHA3-384 hash: 1c1cb9d45c127120e9b62867150acb7419813b8024b6b43e9fede0299d1d0d449bf5359155f7959623167e2d1ba5d09d
SHA1 hash: 2226ef8fc14d779f4ecf2d6c18c7420bc47dd78a
MD5 hash: 338bca6b5cbfea38b9fd6be295e0eeeb
humanhash: gee-eight-india-freddie
File name:338bca6b5cbfea38b9fd6be295e0eeeb.dll
Download: download sample
File size:5'250'632 bytes
First seen:2026-09-29 07:22:50 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 221164accf3692245d776037c1132459
ssdeep 24576:cVI1fu7bL3vcyaOKX3bed+mGitumdrm5JkNULpV30dd0veDfLVFw:oI1f4b8z
TLSH T18836BD6828C57376987392A04FDBB8F1835DE2232633499AB01DE3F507359B89D7271B
TrID 48.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.1% (.EXE) Win64 Executable (generic) (6522/11/2)
7.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.0% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 8c33f0ccc4f07396
Reporter abuse_ch
Tags:dll signed

Code Signing Certificate

Organisation:Riverbend Soft Inc Code Signing
Issuer:Riverbend Soft Inc Code Signing
Algorithm:sha256WithRSAEncryption
Valid from:2026-09-24T14:29:14Z
Valid to:2028-09-24T14:39:14Z
Serial number: 7ec96647259fe78045e840ce72fba8bf
Thumbprint Algorithm:SHA256
Thumbprint: 9e9c4ff47689cdd0efa5026f76d32671ad36d0375c87f8be5c3626503cc310d7
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
172
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm anti-vm base64 evasive overlay packed reconnaissance signed
Verdict:
Malicious
File Type:
dll x32
First seen:
2026-09-25T06:06:00Z UTC
Last seen:
2026-09-29T07:46:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
100 / 100
Signature
AI detected suspicious PE / MSI digital signature
Allocates memory in foreign processes
Changes memory attributes in foreign processes to executable or writable
Contain functionality to detect virtual machines
Contains functionality to detect sandboxes (registry SystemBiosVersion/Date)
Found API chain indicative of debugger detection
Joe Sandbox ML detected suspicious sample
Monitors registry run keys for changes
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
Yara detected AntiVM3
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1979300 Sample: 48ZrXNaohb.dll Startdate: 29/09/2026 Architecture: WINDOWS Score: 100 73 www.google.com 2->73 75 www-mozilla.fastly-edge.com 2->75 77 22 other IPs or domains 2->77 119 Multi AV Scanner detection for submitted file 2->119 121 Yara detected AntiVM3 2->121 123 AI detected suspicious PE / MSI digital signature 2->123 125 Joe Sandbox ML detected suspicious sample 2->125 9 loaddll32.exe 1 2->9         started        11 chrome.exe 2->11 injected 14 msedge.exe 2->14         started        signatures3 process4 dnsIp5 16 rundll32.exe 9->16         started        20 rundll32.exe 9->20         started        22 rundll32.exe 1 9->22         started        26 9 other processes 9->26 97 192.168.2.5 unknown unknown 11->97 24 msedge.exe 14->24         started        process6 dnsIp7 61 blaxllantas.com 16->61 99 System process connects to network (likely due to code injection or exploit) 16->99 101 Changes memory attributes in foreign processes to executable or writable 16->101 103 Tries to harvest and steal browser information (history, passwords, etc) 16->103 28 msedge.exe 16->28         started        30 chrome.exe 16->30         started        63 8.8.8.8, 443, 49742, 49743 GOOGLE-GoogleLLCUS United States 20->63 65 proxy.cobalthaven.cc 172.67.222.158, 443, 49746, 49747 CLOUDFLARENET-CloudflareIncUS Canada 20->65 105 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 20->105 107 Writes to foreign memory regions 20->107 109 Allocates memory in foreign processes 20->109 32 msedge.exe 20->32         started        34 chrome.exe 20->34         started        67 proxy.cobalthaven.cc 22->67 69 blaxllantas.com 162.241.62.130, 443, 49838, 49840 ORACLE-BMC-31898-OracleCorporationUS Brazil 22->69 111 Tries to steal Crypto Currency Wallets 22->111 36 msedge.exe 22->36         started        44 2 other processes 22->44 71 104.21.46.22, 443, 49748 CLOUDFLARENET-CloudflareIncUS Canada 26->71 113 Contains functionality to detect sandboxes (registry SystemBiosVersion/Date) 26->113 115 Found API chain indicative of debugger detection 26->115 117 Contain functionality to detect virtual machines 26->117 40 msedge.exe 26->40         started        42 chrome.exe 26->42         started        46 2 other processes 26->46 signatures8 process9 dnsIp10 48 msedge.exe 28->48         started        50 msedge.exe 32->50         started        79 239.255.255.250 unknown ZZ 36->79 127 Monitors registry run keys for changes 36->127 52 msedge.exe 36->52         started        55 WerFault.exe 36->55         started        57 msedge.exe 40->57         started        59 chrome.exe 42->59         started        81 push.services.mozilla.com 34.107.243.93, 443, 49816 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 44->81 83 normandy.tombstone.experimenter.prod.webservices.mozgcp.net 34.49.51.44, 443, 49812 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 44->83 85 7 other IPs or domains 44->85 signatures11 process12 dnsIp13 87 mr-z01.tm-azurefd.net 150.171.109.72, 443, 49769, 49846 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 52->87 89 ln-0007.ln-msedge.net 150.171.22.17, 443, 49770 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 52->89 95 14 other IPs or domains 52->95 91 142.251.153.119, 443, 49755, 49760 GOOGLE-GoogleLLCUS United States 59->91 93 www.google.com 59->93
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-26 14:37:00 UTC
File Type:
PE (Dll)
Extracted files:
6
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Checks BIOS information in registry
Looks for VMWare Tools registry key
Looks for VMWare services registry key.
Enumerates VirtualBox registry keys
Looks for VirtualBox Guest Additions in registry
Unpacked files
SH256 hash:
12fc543c0e6dfc4b1542117b68bc5a8896e019de213633f65caf797c93a063e9
MD5 hash:
338bca6b5cbfea38b9fd6be295e0eeeb
SHA1 hash:
2226ef8fc14d779f4ecf2d6c18c7420bc47dd78a
SH256 hash:
1c6be0e4b8545d9289e68ed403d8e8d2c0bc0da9ac805af7f04391106d9958c2
MD5 hash:
492188ceaa502e0fcd8d428246f25999
SHA1 hash:
5c8a3e652b4767575c68bca6c7543466d40dcb91
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_Dlls
Rule name:Check_Qemu_Description
Rule name:Check_VBox_Description
Rule name:Check_VBox_Guest_Additions
Rule name:Check_VmTools
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL
Author:ditekSHen
Description:Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WIN_Malware_Unknown_ForgeAuto_e15fb2ad
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments