🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ebfc5b1343c5ec7edfbd7367fd7fd799e874f2dd96e16e640052fcafd1ee2c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1ebfc5b1343c5ec7edfbd7367fd7fd799e874f2dd96e16e640052fcafd1ee2c0
SHA3-384 hash: 44a5f8df01155a2aa0d96dac47ff9b02f6dc7cb6df19327cdd269448f879de79aeb0946475a26d33dac36e2b66cb8fe0
SHA1 hash: 4383e49e929703185b4a866a6cb4b2eb59b25b36
MD5 hash: 4dbca96f0641a603404b49414e6763c3
humanhash: fillet-tennessee-eighteen-idaho
File name:1ebfc5b1343c5ec7edfbd7367fd7fd799e874f2dd96e16e640052fcafd1ee2c0
Download: download sample
File size:92'917'760 bytes
First seen:2026-09-04 20:16:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6538dfb25a4af0bd0d9aaa2acc7b075a
ssdeep 393216:OH0Qt4U5pyl5wyC4UFbc1eAg68OGLalPooZH7LVBEdGiTBxFSsiXUx7WT0wWlF35:OHDmSol5nUX68lL0H9mdG7egURN
TLSH T1CF187E13B3A705D5E8FBDA3196E65123A932BC066F3185DF324C17261F73AE05A3AB11
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon f89efcf8f971f2e0 (10 x NodeLoader, 9 x FixStealer, 6 x Amadey)
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-04 20:42:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Running batch commands
Creating a process with a hidden window
Forced system process termination
DNS request
Launching the process to interact with network services
Launching a process
Creating a file
Creating a file in the %temp% directory
Creating a process from a recently created file
Connection attempt
Creating a window
Sending a custom TCP request
Deleting a recently created file
Using the Windows Management Instrumentation requests
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug crypto fingerprint microsoft_visual_cc reconnaissance
Verdict:
Malicious
Labled as:
TrojanDownloader_Win32_Gomal_bqil
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-28T18:50:00Z UTC
Last seen:
2026-08-19T12:00:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win64.Malware.Generic
Status:
Suspicious
First seen:
2026-07-29 07:41:52 UTC
File Type:
PE+ (Exe)
Extracted files:
15
AV detection:
11 of 36 (30.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution trojan
Behaviour
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
Hide Artifacts: Ignore Process Interrupts
Executes a VBScript file via the Windows Script Host.
Hide Artifacts: Hidden Window
Looks up external IP address via web service
Obfuscated Files or Information: Command Obfuscation
Checks computer location settings
Prevents Microsoft Defender from scanning certain paths by adding an exclusion.
Command and Scripting Interpreter: PowerShell
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments