MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c63dd5c645b215c7dc0e0e4ef509e9394da2669564f79eb4caae43ad59fe0d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 1c63dd5c645b215c7dc0e0e4ef509e9394da2669564f79eb4caae43ad59fe0d6
SHA3-384 hash: 3aa2d03077abe224833ff63213ec7f6e369e1581a81c0d0f42c86b1782499613c1e178b3d7a9a2e3858ae43307c6e8d3
SHA1 hash: a7235131432fd890072a0ab88e25333394630020
MD5 hash: 411a3840b936261298a9907a3f4d42e5
humanhash: romeo-asparagus-mike-fillet
File name:file
Download: download sample
File size:443'904 bytes
First seen:2026-03-06 12:00:56 UTC
Last seen:2026-03-06 12:31:52 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 6702f1bd13a4e9743588bf4e6892ab6a
ssdeep 6144:0TzDNAjPol0E0Y4NiCVaU06dNsOz4zaQwOo62NoNgVzJ7BRHJCP/2a9TYrJCfA/H:szK0leo+SO99X6EoNgr7BRHJma/UnNA
TLSH T1519423EA118DC0BCC9A925BA452234AD762E215CFF67DF220D2AFE7F158884C36547C6
TrID 38.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
15.6% (.ICL) Windows Icons Library (generic) (2059/9)
15.4% (.EXE) OS/2 Executable (generic) (2029/13)
15.2% (.EXE) Generic Win/DOS Executable (2002/3)
15.2% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-amadey exe fbf543


Avatar
Bitsight
url: http://158.94.211.222/files/6149304756/9MVYpgf.exe

Intelligence


File Origin
# of uploads :
12
# of downloads :
118
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
file
Verdict:
No threats detected
Analysis date:
2026-03-06 12:03:49 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug hacktool overlay packed
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
1c63dd5c645b215c7dc0e0e4ef509e9394da2669564f79eb4caae43ad59fe0d6
MD5 hash:
411a3840b936261298a9907a3f4d42e5
SHA1 hash:
a7235131432fd890072a0ab88e25333394630020
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 1c63dd5c645b215c7dc0e0e4ef509e9394da2669564f79eb4caae43ad59fe0d6

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

Comments