MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1908667a279616de082f9f3a196fc1710ce5be9c85bdb2fe7100192f4d8d42f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RustyStealer


Vendor detections: 12


Intelligence 12 IOCs YARA 20 File information Comments

SHA256 hash: 1908667a279616de082f9f3a196fc1710ce5be9c85bdb2fe7100192f4d8d42f2
SHA3-384 hash: 0ca7e41a95603cfdc1ca8da67d937bf896e5282e9e7880fcdc776bac209e7928002832aff0cadda61a9e10c3314ca3f7
SHA1 hash: 6f7df270bd72bf3119403da9e738f7df8015813a
MD5 hash: ed73908c65575cae4ae7debf23220056
humanhash: lactose-fillet-salami-earth
File name:Protokol_Prioretnoy_Proverki_Obektov_KVO_19.05.2026.pdf.exe
Download: download sample
Signature RustyStealer
File size:3'408'384 bytes
First seen:2026-06-08 08:13:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 713ff4dd0f30035a9e8c8c906d73a028 (1 x RustyStealer)
ssdeep 24576:um+l+pISlYd2hsT1ORfXC9DomS4g+g7Qv/d3rmsrP1YtwUKBll6NqidVLnyx:umO+9YMhoMfyBbTlrmsr1YuUk4ZVLy
TLSH T131F55B43F28584EDC45EC079862B9632B633BC8906306A6F16A4FB253F76B511F1EF19
TrID 45.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
18.0% (.EXE) Win64 Executable (generic) (6522/11/2)
13.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.6% (.ICL) Windows Icons Library (generic) (2059/9)
5.6% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon f8dc988898a894b8 (3 x AveMariaRAT, 2 x RedLineStealer, 1 x QuasarRAT)
Reporter smica83
Tags:exe RUS RustyStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Protokol_Prioretnoy_KVO.rar
Verdict:
Malicious activity
Analysis date:
2026-05-21 04:20:08 UTC
Tags:
evasion ip-check stealer telegram arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
underscore infosteal
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Creating a process from a recently created file
Creating a file in the %temp% directory
Launching a process
Creating a window
Deleting a recently created file
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Running batch commands
Using the Windows Management Instrumentation requests
Launching the process to interact with network services
Searching for synchronization primitives
Deleting of the original file
Gathering data
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-20T10:20:00Z UTC
Last seen:
2026-06-08T07:43:00Z UTC
Hits:
~100
Detections:
Trojan-Downloader.Win32.Paph.pun
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Deletes itself after installation
Encrypted powershell cmdline option found
Found direct / indirect Syscall (likely to bypass EDR)
Gathers network related connection and port information
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Initial sample is a PE file and has a suspicious name
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs a network lookup / discovery via ARP
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sigma detected: Check external IP via Powershell
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Double Extension File Execution
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: System File Execution Location Anomaly
Sigma detected: Windows Binaries Write Suspicious Extensions
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Uses ipconfig to lookup or modify the Windows network settings
Uses netstat to query active network connections and open ports
Uses the Telegram API (likely for C&C communication)
Uses whoami command line tool to query computer and username
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1924288 Sample: Protokol_Prioretnoy_Proverk... Startdate: 08/06/2026 Architecture: WINDOWS Score: 100 77 api.telegram.org 2->77 79 api.ipify.org 2->79 87 Suricata IDS alerts for network traffic 2->87 89 Malicious sample detected (through community Yara rule) 2->89 91 Antivirus / Scanner detection for submitted sample 2->91 95 15 other signatures 2->95 10 Protokol_Prioretnoy_Proverki_Obektov_KVO_19.05.2026.pdf.exe 3 2->10         started        signatures3 93 Uses the Telegram API (likely for C&C communication) 77->93 process4 file5 61 C:\Users\user\...61XLog Community Edition.exe, PE32+ 10->61 dropped 63 C:\Users\user\...\????_?_??_????????.pdf, PDF 10->63 dropped 65 C:\Users\user\AppData\...\cleanup_dropper.vbs, ASCII 10->65 dropped 113 Suspicious powershell command line found 10->113 115 Found direct / indirect Syscall (likely to bypass EDR) 10->115 14 NXLog Community Edition.exe 48 10->14         started        18 wscript.exe 10->18         started        20 powershell.exe 3 12 10->20         started        signatures6 process7 file8 75 C:\Users\user\AppData\...\RuntimeBroker.exe, PE32+ 14->75 dropped 117 Suspicious powershell command line found 14->117 119 Encrypted powershell cmdline option found 14->119 121 Tries to harvest and steal browser information (history, passwords, etc) 14->121 125 2 other signatures 14->125 22 cmd.exe 14->22         started        25 RuntimeBroker.exe 14->25         started        29 powershell.exe 14->29         started        35 14 other processes 14->35 123 Deletes itself after installation 18->123 31 Acrobat.exe 20 57 20->31         started        33 conhost.exe 20->33         started        signatures9 process10 dnsIp11 97 Uses netstat to query active network connections and open ports 22->97 99 Uses ipconfig to lookup or modify the Windows network settings 22->99 101 Uses whoami command line tool to query computer and username 22->101 37 conhost.exe 22->37         started        39 tzutil.exe 22->39         started        83 api.telegram.org 149.154.166.110, 443, 49709, 49710 TELEGRAMVG United Kingdom 25->83 67 C:\Users\user\AppData\...\cleanup_sender.vbs, ASCII 25->67 dropped 103 Multi AV Scanner detection for dropped file 25->103 105 Found direct / indirect Syscall (likely to bypass EDR) 25->105 41 wscript.exe 25->41         started        69 C:\...\user-PC_20260608_055042__part01.zip, Zip 29->69 dropped 107 Loading BitLocker PowerShell Module 29->107 43 conhost.exe 29->43         started        45 AcroCEF.exe 105 31->45         started        85 api.ipify.org 104.26.12.205, 443, 49693 CLOUDFLARENET-CloudflareIncUS Canada 35->85 71 C:\Users\user\AppData\...\screenshot.png, PNG 35->71 dropped 73 C:\Users\user\...\processes_modules.txt, Unicode 35->73 dropped 109 Gathers network related connection and port information 35->109 111 Performs a network lookup / discovery via ARP 35->111 47 systeminfo.exe 35->47         started        50 net.exe 35->50         started        52 conhost.exe 35->52         started        54 21 other processes 35->54 file12 signatures13 process14 signatures15 56 AcroCEF.exe 45->56         started        127 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 47->127 59 net1.exe 50->59         started        process16 dnsIp17 81 72.247.96.179, 443, 49704 AKAMAI-AS-AkamaiTechnologiesIncUS United States 56->81
Gathering data
Verdict:
Malicious
Threat:
Trojan-Downloader.Win32.Paph
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-21 00:57:29 UTC
File Type:
PE+ (Exe)
Extracted files:
22
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware discovery execution spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Gathers network information
Gathers system information
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Location Discovery: System Language Discovery
System Network Connections Discovery
System Time Discovery
Drops file in Windows directory
Looks up external IP address via web service
Network Service Discovery
Deletes itself
Executes dropped EXE
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
1908667a279616de082f9f3a196fc1710ce5be9c85bdb2fe7100192f4d8d42f2
MD5 hash:
ed73908c65575cae4ae7debf23220056
SHA1 hash:
6f7df270bd72bf3119403da9e738f7df8015813a
SH256 hash:
0324d1a0c01db9de583ef9a0691943f0b214b13cc05484d40588c7f86c366e51
MD5 hash:
752c8ce292e9d21ff5bb41e2eb6be638
SHA1 hash:
cb77ec5d3120509a9418da6d423e1f64a71acdc3
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:pe_detect_tls_callbacks
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Rustyloader_mem_loose
Author:James_inthe_box
Description:Corroded buerloader
Reference:https://app.any.run/tasks/83064edd-c7eb-4558-85e8-621db72b2a24
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TelegramAPIMalware_PowerShell_EXE
Author:@polygonben
Description:Hunting for pwsh malware using Telegram for C2
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:WIN_ClickFix_Detection
Author:dogsafetyforeverone
Description:Detects ClickFix social engineering technique using 'Verify you are human' messages and malicious PowerShell commands
Reference:ClickFix social engineering and malicious PowerShell commands

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments