MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1cec90906b40fa7e29f0cd531d3bbcfc19f6e03fd99b5c41b5dbce8270652460. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 6


Intelligence 6 IOCs YARA 21 File information Comments

SHA256 hash: 1cec90906b40fa7e29f0cd531d3bbcfc19f6e03fd99b5c41b5dbce8270652460
SHA3-384 hash: 8339a2a7d12aced93bce02afc94f29046076128b3e9b720949ac782518f6a8544d44d92d18fa54b59b8f5701bbaa3d62
SHA1 hash: 0c6ce76aa4f1f7e97b16d8d02624177fc43e5381
MD5 hash: e7b70279f1bf7cc8c274e7ca8f7a9f46
humanhash: hotel-carolina-kansas-kitten
File name:package
Download: download sample
Signature KongTuke
File size:16'872'425 bytes
First seen:2026-07-24 16:10:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:WMhQiYtub3FteY07Bc5X5fx145/1iREIhm87N75TAg3mJw1fsFi1y:dhQnturFteY0m5X5PUtUhdp5TCJ+kc1y
TLSH T1E807337CC9427798EA5E611600D29FD2F9C24C584A625D3B3C0A7DDE11A3F1FAB21BC6
Magika zip
Reporter monitorsg
Tags:Kongtuke zip


Avatar
monitorsg
hXXps://marshalh[.]icu/c9lg2uqb.js (ClickFucker) --> hXXps://marshalh[.]icu/api/v1/session (token) --> hXXps://marshalh[.]icu/api/v1/verify (gateway) --> hXXps://marshalh[.]icu/api/v1/status (clipboard) --> hXXps://hosthex9101[.]com/update/package (tar)

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
US US
File Archive Information

This file archive contains 22 file(s), sorted by their relevance:

File name:xul.dll
File size:8'611'840 bytes
SHA256 hash: e2132030c24169e9e615d1dc9f9e2c88f1c3036fdda5e0e6de8a46fe20c64fd9
MD5 hash: e68230b76b25974350f96d0b21cc61d4
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.manifest
File size:240 bytes
SHA256 hash: 23680bbba9edbbfab98e27f9bd676b031da3b20adfe909ce86c9ecc1b8bb80d1
MD5 hash: 5d5e62ad6d1023592406fe3ea1f0ea75
MIME type:text/xml
Signature KongTuke
File name:vcruntime140_1.dll
File size:47'264 bytes
SHA256 hash: e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
MD5 hash: 03b43160d21c08de07a79d0a1c5ee81d
MIME type:application/x-dosexec
Signature KongTuke
File name:AccessibleMarshal.dll
File size:939'520 bytes
SHA256 hash: 334227091de1ffdae2db72dc96b07cf8d49bf1513233073d8deff2ee952e3fc8
MD5 hash: a7b57ab4f16c31d61217bf15212e6e91
MIME type:application/x-dosexec
Signature KongTuke
File name:gkcodecs.dll
File size:939'520 bytes
SHA256 hash: 16f817c46046f13edf66fb1d107812cd7991f106ef4cc79d69e0ca708b504394
MD5 hash: 97fb67dd3aabdbb969ab402a578b7280
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.dll
File size:850'944 bytes
SHA256 hash: 6387c174ecb1ac018f9f82d1603485690facbf345687889cd2ca1a9e2248467f
MD5 hash: b9eb1af67b5fa55bf4648a57c6f00378
MIME type:application/x-dosexec
Signature KongTuke
File name:plugin-container.exe
File size:144'512 bytes
SHA256 hash: b2f2b9a3a712125a06b303344b7a0dc57f91ee6f1749c731ca2260931dbe24e9
MD5 hash: 65729157b053d4d373595f7a53126298
MIME type:application/x-dosexec
Signature KongTuke
File name:wmfclearkey.dll
File size:892'416 bytes
SHA256 hash: e08b65072055a9b12af9f4126c9078dfbb5e18b3bbd51136bfa7a2dd496e8742
MD5 hash: 6af23ecc7f3670e9bf568a35e342df2c
MIME type:application/x-dosexec
Signature KongTuke
File name:freebl3.dll
File size:939'520 bytes
SHA256 hash: 72a79fad777ce4b5794dd71b4ad9c3f2e90f0fd6659047229978719d16a8be1b
MD5 hash: aa1ce12babeb394e11fbb096384a7749
MIME type:application/x-dosexec
Signature KongTuke
File name:mozinference.dll
File size:939'520 bytes
SHA256 hash: 2e8cb8c3d289b4b81bda4693e325474a2fbcd3da703bcb47fb2efc137f84a561
MD5 hash: 063b60e09af83f50e6c3f1a26ed03414
MIME type:application/x-dosexec
Signature KongTuke
File name:vcruntime140.dll
File size:123'472 bytes
SHA256 hash: 184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
MD5 hash: 0d35c5e99871b4f02c490b9fd9dace34
MIME type:application/x-dosexec
Signature KongTuke
File name:nss3.dll
File size:940'032 bytes
SHA256 hash: 412c603981ef9c972ea8a7af63cec4b7e5748b7b5087aaf584aff25d2b85bb2a
MD5 hash: 84dfebc12209c25d1fe0ba719b636e27
MIME type:application/x-dosexec
Signature KongTuke
File name:libEGL.dll
File size:3'077'632 bytes
SHA256 hash: b4273fe35bc774b44c2a99f08a5289da77e8076b74f2fc3b2f1cd133a831d513
MD5 hash: a898c08167223946700b78592690b4d2
MIME type:application/x-dosexec
Signature KongTuke
File name:libGLESv2.dll
File size:3'091'456 bytes
SHA256 hash: 0bfd2458ddb062432ad6a1f71f8277f44001ba04c43a0e905d0919431af28f77
MD5 hash: cc4c5b7b490c1ba5ca51264ccfa730c0
MIME type:application/x-dosexec
Signature KongTuke
File name:nssutil3.dll
File size:6'480'896 bytes
SHA256 hash: 5623905a55b1085e8998ab168b97b623def1a823e97fa67ccb4916bee3f2d1fb
MD5 hash: 12b21380cfad53a7b34629ecc21ee3c3
MIME type:application/x-dosexec
Signature KongTuke
File name:notificationserver.dll
File size:838'144 bytes
SHA256 hash: 0ec5760606d17fccdded0d4c14ec797f8410701836617dba21d372e543d1c7e2
MD5 hash: 9060f982e6e9cfea2e1d61f7b94f27ff
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavcodec.dll
File size:1'102'336 bytes
SHA256 hash: c2d80f0da0427d29bed0f7b2349e26d8c14cde1058591181f1533cac042c8e65
MD5 hash: d7a8b63b194148f3d5f5dd13b30ba5d7
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavutil.dll
File size:3'076'608 bytes
SHA256 hash: 98cb064aaa6ff96e2058bdf403550e9d4aea900ccca3a3519a6e6929a10d7a37
MD5 hash: 860e35189c877ecaa9bc8b1bcb87df9d
MIME type:application/x-dosexec
Signature KongTuke
File name:msvcp140.dll
File size:553'552 bytes
SHA256 hash: def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
MD5 hash: 4e3fa9bd90ef020c14359639dc19312b
MIME type:application/x-dosexec
Signature KongTuke
File name:mozwer.dll
File size:939'520 bytes
SHA256 hash: 583ccf7ed66ae3e91753af600394019a011369601e23305a34f85d364f8ebbf8
MD5 hash: 2107668048ad245e6a8d6c922fe23a45
MIME type:application/x-dosexec
Signature KongTuke
File name:lgpllibs.dll
File size:940'032 bytes
SHA256 hash: dd6986d782036a6575755bbe6f0b33f73e3ad29358f9b32022e8de8cb59d9faf
MD5 hash: fbda825c577b328eb8fb02250eeffdf5
MIME type:application/x-dosexec
Signature KongTuke
File name:softokn3.dll
File size:940'544 bytes
SHA256 hash: b7183e4fdd34147cd79bd976222027d8a97f3d104d57d75c112eb659f87f7ca4
MD5 hash: 2600240ab3818605079f828bcee70459
MIME type:application/x-dosexec
Signature KongTuke
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.Wacatac
Status:
Malicious
First seen:
2026-07-24 16:13:39 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

zip 1cec90906b40fa7e29f0cd531d3bbcfc19f6e03fd99b5c41b5dbce8270652460

(this sample)

  
Delivery method
Distributed via web download

Comments