MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27e2441ecc756fe8e91a3cbf26ee4e1283f97c8f4b6c36349102775b30f9ff7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LegionLoader


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 27e2441ecc756fe8e91a3cbf26ee4e1283f97c8f4b6c36349102775b30f9ff7d
SHA3-384 hash: cb7da742225ae9a104fb9526223ae9bcf6f88a7f1cdd9034c6c25e1e268f78f9bd12b04d232982f05d68bd185e371f06
SHA1 hash: 878e2292f38d20bd32207932fb6d88b9315723f2
MD5 hash: 983b9bcad7a2e9d597061217ec6acddb
humanhash: october-two-paris-white
File name:File_Open v.5.2.7z
Download: download sample
Signature LegionLoader
File size:38'492'725 bytes
First seen:2025-12-10 19:44:25 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 786432:WRVka6ObFsCEempZXmm0vuKBm9dAxwNaNx6dxpYl13Ss4Yg:Wn0aFsrpZWTvxm3AxgaNxBV4D
TLSH T1BA8733F8EA1319188227E8F5AE905E0577FDCD8754F5FF0B0A91C8E349921BD8E28E54
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:7z dllHijack LegionLoader


Avatar
iamaachum
api.instabeatleepesaveo.cloud => https://mega.nz/file/bx4FHRAZ#i4ylAhvOE35dzMV3Fh3EowhTOM_cXR-TQwMKcMQxfXc

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
ES ES
File Archive Information

This file archive contains 6 file(s), sorted by their relevance:

File name:vcruntime140_1.dll
File size:52'304 bytes
SHA256 hash: ae1dd66cf1345491f13d460b0580d2fb5c6b8e7a24bed440c7cee6318cc389ea
MD5 hash: f877e4e147b59e870f37cae33de0493c
MIME type:application/x-dosexec
Signature LegionLoader
File name:data.bin
File size:478'707 bytes
SHA256 hash: 1792eaba041b19f0e1961a5282885ded030a1e2d9b39e6147b230b44b99bf614
MD5 hash: 62cf3f025e7f68045b1125428ec47dee
MIME type:application/octet-stream
Signature LegionLoader
File name:setup.exe
File size:3'080'096 bytes
SHA256 hash: a0657b6cc937534d9dda18de95e41a108f6030d63ff3aa105b2fa78c8aac6af3
MD5 hash: e614ae2c3840113f11833a1db00650ad
MIME type:application/x-dosexec
Signature LegionLoader
File name:sqlite.dll
File size:128'820 bytes
SHA256 hash: 12d7fa0220b7370737fd02fe72f1d4b2bb8063d9aa7109fa0e535e39d8e25bfc
MD5 hash: c99531a968d7cb6983cdd7a0a03502b8
MIME type:application/x-dosexec
Signature LegionLoader
File name:vcruntime140.dll
File size:127'056 bytes
SHA256 hash: b1b933beee9a06842e29f0005bc7fa8b82626fb0922863f61eea9ca0491fbe40
MD5 hash: 5c8a44742138e87cdff02ce38e83c33f
MIME type:application/x-dosexec
Signature LegionLoader
File name:msvcp140.dll
File size:557'728 bytes
SHA256 hash: 0f885b509a685d2bbfa652fed26b5fb31d88fbdab0a978c641d1c7b8aa460aa9
MD5 hash: bc88b387cafa556068b5c5d6ff3ccc8f
MIME type:application/x-dosexec
Signature LegionLoader
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc virus
Gathering data
Gathering data
Threat name:
Win64.Trojan.Rhadamanthys
Status:
Malicious
First seen:
2025-12-10 19:45:32 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LegionLoader

7z 27e2441ecc756fe8e91a3cbf26ee4e1283f97c8f4b6c36349102775b30f9ff7d

(this sample)

  
Delivery method
Distributed via web download

Comments