MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 136c640c2e8fa24a757f072ab07e41563cb178852282fcf4fa36572df94b7fac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: 136c640c2e8fa24a757f072ab07e41563cb178852282fcf4fa36572df94b7fac
SHA3-384 hash: 3b38ba620ed3808c26d11880fe7abe4dafa5b2eb495e863b34d696c8ff08ff9f7c72caa5845f831ee70f9e24df4743a9
SHA1 hash: 60ceaf2dbaa5e8ef6a250bc24796267010fd0201
MD5 hash: 92dd94e1d6bd1288c355e846c6093088
humanhash: hot-zebra-table-sweet
File name:file
Download: download sample
File size:1'672'704 bytes
First seen:2026-08-16 18:30:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash de85a398477c39117ee5fd3f2278b959
ssdeep 24576:EKV1SCStqB6AnKbqhuaogtJ4XLTv8aOO1B2F3/f28XLbrMbvuqdLt:E01Atk6SwkuaoMSXLTv8ou32
TLSH T153750187AED115F8D193803C929E2A5BF239310967199EFB72DC12543F1628D987CB2F
TrID 38.2% (.EXE) Win64 Executable (generic) (6522/11/2)
26.4% (.EXE) Win32 Executable (generic) (4504/4/1)
11.8% (.EXE) OS/2 Executable (generic) (2029/13)
11.7% (.EXE) Generic Win/DOS Executable (2002/3)
11.7% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 3030323232b2b2b2
Reporter Bitsight
Tags:974b6b4ed30ddaa4b6f4ec27976e52d8 dropped-by-Remus exe


Avatar
Bitsight
url: https://thu-iphone-07.cfd/PithnoModule.exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-16 20:46:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-debug microsoft_visual_cc
Verdict:
Unknown
File Type:
exe x64
First seen:
2026-08-16T12:20:00Z UTC
Last seen:
2026-08-16T14:03:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
136c640c2e8fa24a757f072ab07e41563cb178852282fcf4fa36572df94b7fac
MD5 hash:
92dd94e1d6bd1288c355e846c6093088
SHA1 hash:
60ceaf2dbaa5e8ef6a250bc24796267010fd0201
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 136c640c2e8fa24a757f072ab07e41563cb178852282fcf4fa36572df94b7fac

(this sample)

  
Dropped by
Remus
  
Delivery method
Distributed via web download

Comments