MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 145a70dec0dc951f7cf55e10a755399773ae3d5bc9d38cfde6095cc88c7a3bb1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 7 File information Comments

SHA256 hash: 145a70dec0dc951f7cf55e10a755399773ae3d5bc9d38cfde6095cc88c7a3bb1
SHA3-384 hash: 87dd32475258879a4c116c1cc13bb99c95a9ca0ea1e5285db0295879ab0286ac5ba519e8c740f7953fdad610c2fc6952
SHA1 hash: 885a107f755eb39bfef53d887b6f008663e22567
MD5 hash: 154874f9b722bc699bc503dd1469be87
humanhash: lamp-nine-spaghetti-april
File name:154874f9b722bc699bc503dd1469be87.exe
Download: download sample
File size:429'568 bytes
First seen:2026-08-20 06:04:38 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'197 x AgentTesla, 20'351 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 6144:kIiVFC/lnJDBgeNEiTvOYWt/9LlgftukHDL00lYjezowMabOOEz:KoJ9geNOYWdveXDRlYSzHVO
TLSH T189943A7A32914F21C24A1773C1C7590087E6964776ABFB0B328513DB2D863FEDA4B297
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
SE SE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Launching a process
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Creating a file in the %AppData% directory
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 loader net_reactor obfuscated obfuscated packed purelogsstealer
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Encrypted powershell cmdline option found
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
13 match(es)
Tags:
.Net .Net Obfuscator .Net Reactor Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.91 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.PureLogStealer
Status:
Malicious
First seen:
2026-07-25 06:24:32 UTC
AV detection:
24 of 37 (64.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
145a70dec0dc951f7cf55e10a755399773ae3d5bc9d38cfde6095cc88c7a3bb1
MD5 hash:
154874f9b722bc699bc503dd1469be87
SHA1 hash:
885a107f755eb39bfef53d887b6f008663e22567
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
1521a4d570c50deca1fee4ae142f3b31156d39d655733421a3d28f014c091456
MD5 hash:
bade3ff39ab85b636f3b971811882897
SHA1 hash:
2ce35a99c8e84717c58914f80682baf3fad82aae
SH256 hash:
50e6e7242a8178b913632fb4cd0a22fae432d52270a228500d3e5eeebc1b1b42
MD5 hash:
29dce48b8d2d534abfd12f44c2c87f36
SHA1 hash:
6e630f6883d29843d7f8ca8b74195c26c037d9ad
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
145a70dec0dc951f7cf55e10a755399773ae3d5bc9d38cfde6095cc88c7a3bb1
MD5 hash:
154874f9b722bc699bc503dd1469be87
SHA1 hash:
885a107f755eb39bfef53d887b6f008663e22567
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Lumma_Stealer_Detection
Author:ashizZz
Description:Detects a specific Lumma Stealer malware sample using unique strings and behaviors
Reference:https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments