MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1d6979a176da38de6b35ccfa4058a94b00cd76d0e9201229344d7af0e0770baa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 10 File information Comments

SHA256 hash: 1d6979a176da38de6b35ccfa4058a94b00cd76d0e9201229344d7af0e0770baa
SHA3-384 hash: 77eddc3fe9e7b43ae9e9e8a857ed82653f512c66e4e969e0ea0d962960b56d46e2fd3d1128155e0e21dfeeb252dee90e
SHA1 hash: 965c91da8ccea1721704f418124087cbef2a8f00
MD5 hash: 0b35bdc91cdea843a9b9b1b0fc006aba
humanhash: undress-montana-network-sierra
File name:0b35bdc91cdea843a9b9b1b0fc006aba.exe
Download: download sample
File size:64'788'976 bytes
First seen:2026-08-25 14:35:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'199 x AgentTesla, 20'363 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 1572864:8vk3X98hUUspqcvokD3yxUTvk3X98hUUspqcvokD3yxU6n:1QCBOxUYQCBOxUa
TLSH T11EE733B134834836D5826CB096E6C364C1E60D908E752563A57AB2BFD6F36C296F73E0
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
123
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Adding a root certificate
Creating a service
Moving a file to the Program Files subdirectory
Running batch commands
Launching the default Windows debugger (dwwin.exe)
Creating a file in the %temp% subdirectories
Launching a process
Creating a file
Сreating synchronization primitives
Creating a window
Modifying a system file
Creating a file in the Windows subdirectories
Creating a file in the Program Files subdirectories
Moving a recently created file
Replacing files
Creating a process from a recently created file
Connection attempt
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Deleting a recently created file
Enabling autorun for a service
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug dropper fingerprint installer-heuristic lolbin msiexec overlay packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-21T17:04:00Z UTC
Last seen:
2026-08-27T03:44:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Changes security center settings (notifications, updates, antivirus, firewall)
Enables network access during safeboot for specific services
Installs new ROOT certificates
Multi AV Scanner detection for submitted file
Potential context-aware VBS script found (checks for environment specific values)
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes or reads registry keys via WMI
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1963414 Sample: sd7aICV84S.exe Startdate: 25/08/2026 Architecture: WINDOWS Score: 100 100 Antivirus / Scanner detection for submitted sample 2->100 102 Multi AV Scanner detection for submitted file 2->102 104 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 2->104 106 3 other signatures 2->106 8 msiexec.exe 456 210 2->8         started        11 dcagentservice.exe 2->11         started        13 sd7aICV84S.exe 8 2->13         started        15 8 other processes 2->15 process3 dnsIp4 86 C:\Program Files (x86)\...\dcconfig.exe, PE32 8->86 dropped 88 C:\...\dcagentregister.exe, PE32 8->88 dropped 90 C:\Windows\SysWOW64\dclibxml2.dll, PE32 8->90 dropped 94 16 other files (none is malicious) 8->94 dropped 19 dcagentregister.exe 55 66 8->19         started        23 msiexec.exe 8->23         started        25 dcinventory.exe 11->25         started        27 dcconfig.exe 11->27         started        29 dcusbsummary.exe 11->29         started        35 14 other processes 11->35 92 C:\Users\user\AppData\...\sd7aICV84S.exe.log, CSV 13->92 dropped 31 msiexec.exe 1 13->31         started        96 127.0.0.1 unknown unknown 15->96 126 Changes security center settings (notifications, updates, antivirus, firewall) 15->126 33 conhost.exe 15->33         started        file5 signatures6 process7 dnsIp8 98 182.16.91.30, 49710, 49712, 49713 NETSEC-HKNetsecLimitedHK Hong Kong SAR China 19->98 108 Installs new ROOT certificates 19->108 110 Enables network access during safeboot for specific services 19->110 37 7za.exe 19->37         started        41 cmd.exe 19->41         started        43 dcpatchscan.exe 19->43         started        45 dcstatusutil.exe 19->45         started        112 Tries to detect sandboxes / dynamic malware analysis system (Installed program check) 25->112 47 conhost.exe 25->47         started        49 dcinventory.exe 27->49         started        51 conhost.exe 27->51         started        53 dcusb64.exe 29->53         started        114 Potential context-aware VBS script found (checks for environment specific values) 31->114 55 9 other processes 35->55 signatures9 process10 file11 72 C:\Program Files (x86)\...\dcstatusutil.exe, PE32 37->72 dropped 74 C:\Program Files (x86)\...\dcinventory.exe, PE32 37->74 dropped 76 C:\Program Files (x86)\...\wsClientSocket.dll, PE32 37->76 dropped 84 69 other files (none is malicious) 37->84 dropped 116 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 37->116 57 conhost.exe 37->57         started        60 systeminfo.exe 41->60         started        62 conhost.exe 41->62         started        78 C:\Program Files (x86)\...\drvforceupdate.exe, PE32+ 43->78 dropped 80 C:\Program Files (x86)\...\dcpatchutils.dll, PE32 43->80 dropped 82 C:\...\dcdriverupdates.dll, PE32 43->82 dropped 64 conhost.exe 43->64         started        66 conhost.exe 45->66         started        68 conhost.exe 49->68         started        70 conhost.exe 53->70         started        signatures12 process13 signatures14 118 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 57->118 120 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 57->120 122 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 60->122 124 Writes or reads registry keys via WMI 60->124
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-21 12:20:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution persistence spyware trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Gathers system information
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Executes a command shell one-liner
Modifies trusted root certificate store through registry
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Executes a VBScript file via the Windows Script Host.
Badlisted process makes network request
Checks installed software on the system
Enumerates connected drives
Power Settings
Executes dropped EXE
Loads dropped DLL
Drops file in Drivers directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments