MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 27b0966ea2f59ab7be692b4d5f0afda4e54f14b4de7b87922676b1ff4fda0bf0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 27b0966ea2f59ab7be692b4d5f0afda4e54f14b4de7b87922676b1ff4fda0bf0 |
|---|---|
| SHA3-384 hash: | 89547a08e0225d48b6e7f6f77fab0254a75e65fd568399c198d51416a4b7238b43f6d58274b9a4638c6bc6147e64fb7c |
| SHA1 hash: | eae2829d8bbf87e524dda37ccf236aff19b1abf6 |
| MD5 hash: | f661fa469cb605573cc6ebd3a8285358 |
| humanhash: | beryllium-rugby-robert-kentucky |
| File name: | SecuriteInfo.com.Win64.MalwareX-gen.69513216 |
| Download: | download sample |
| File size: | 91'401'480 bytes |
| First seen: | 2026-08-27 00:05:19 UTC |
| Last seen: | 2026-08-27 10:14:14 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 72b8a50094622ae17e4a01784f543b8b |
| ssdeep | 1572864:8vr6TvS2oF+YZhS4I+sNo7vcF7DZg/wI20iAfNgQfvI41HTntifnK:+6DSKydAo7UFSwI2JcvhHTntQK |
| TLSH | T15F183373EA65C8F8DE5782346DE6DFB2A1F4F20952F7ED1EA04EC10638651E02405B7A |
| TrID | 45.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 18.0% (.EXE) Win64 Executable (generic) (6522/11/2) 13.9% (.EXE) Win16 NE executable (generic) (5038/12/1) 5.6% (.ICL) Windows Icons Library (generic) (2059/9) 5.6% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| dhash icon | 70f0d4d4d4cce870 (1 x CoinMiner) |
| Reporter | |
| Tags: | exe signed |
Code Signing Certificate
| Organisation: | Corvus Pack 36a382cb |
|---|---|
| Issuer: | Corvus Pack 36a382cb |
| Algorithm: | ecdsa-with-SHA256 |
| Valid from: | 2026-08-25T09:25:17Z |
| Valid to: | 2026-08-27T10:25:17Z |
| Serial number: | db15c9314101dc1458a19050aedbc045 |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | 99a6fb43226ac495dcfb09fe6df5c8c79e8edb083223229445f1b0142c49cf81 |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
Intelligence
File Origin
# of uploads :
3
# of downloads :
208
Origin country :
FRVendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-27 00:14:57 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
DNS request
Connection attempt
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Sending an HTTP POST request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm crypto explorer hacktool installer-heuristic lolbin overlay packed packed reconnaissance short-lived-cert signed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-26T05:03:00Z UTC
Last seen:
2026-08-28T22:03:00Z UTC
Hits:
~100
Score:
96%
Verdict:
Malware
File Type:
PE
Gathering data
Threat name:
Win64.Dropper.Generic
Status:
Suspicious
First seen:
2026-08-26 10:14:39 UTC
File Type:
PE+ (Exe)
Extracted files:
9
AV detection:
10 of 24 (41.67%)
Threat level:
3/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
10/10
Tags:
persistence
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Executes dropped EXE
Suspicious use of NtCreateUserProcessOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe 27b0966ea2f59ab7be692b4d5f0afda4e54f14b4de7b87922676b1ff4fda0bf0
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.