🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d499700e1319d9203e322cb1e8a8cfec4aa997f86d1fcf76156cfaa0a72054c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GOBackdoor


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 2d499700e1319d9203e322cb1e8a8cfec4aa997f86d1fcf76156cfaa0a72054c
SHA3-384 hash: 03a20ea4e68852f2aff2116fc293aa2719c23290ea6a37a2dad84af5dafed939164d5b90a06abc3c927d441c8d935f08
SHA1 hash: 0f8aafc5808faa6efc4ba8ef98b8880f256fb101
MD5 hash: 59c1b29677ef1ac61bc12fec9d8cd816
humanhash: connecticut-violet-steak-india
File name:schd.dll
Download: download sample
Signature GOBackdoor
File size:12'524'112 bytes
First seen:2025-09-17 18:22:05 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 7cebca2b4869e885be5d2060bc9f5e88 (1 x GOBackdoor)
ssdeep 24576:rFedDJa5W6btzDTxOU4ZZIi5W0LM1VS4rK3mUe4s4T7cZ8Gz1Uq3OUts2BKEzj9Y:rFYa5W6BnTxOKWN
TLSH T18EC65C776FB1AC42CBCB02775DA66F980EEE4731418A70C9D1AB42C00557AF7EA0E52D
TrID 30.2% (.EXE) Win64 Executable (generic) (10522/11/4)
18.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
14.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
12.9% (.EXE) Win32 Executable (generic) (4504/4/1)
5.9% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter aachum
Tags:dll dropped-by-ACRStealer GOBackdoor signed

Code Signing Certificate

Organisation:Qihoo 360 Technology Ltd
Issuer:Qihoo 360 Technology Ltd
Algorithm:sha1WithRSA
Valid from:2018-12-31T23:00:00Z
Valid to:2098-12-31T23:00:00Z
Serial number: -3b26472c3736bf62bd782c8675aaece1
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 355f429b04060c796462ef121e9a0809128642526da08519b9f9e056767cdb0d
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
iamaachum
http://mi.raisindispose.com/kaWt2QXfpPueNM/F.ct/schd.dll

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
ES ES
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug anti-vm mingw packed redcap signed
Verdict:
Malicious
File Type:
dll x32
First seen:
2025-09-17T15:28:00Z UTC
Last seen:
2025-09-17T15:28:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan.Win32.ExShell.gen
Malware family:
Driver Support
Verdict:
Suspicious
Result
Threat name:
GO Backdoor
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
AI detected suspicious PE digital signature
Antivirus detection for URL or domain
Connects to many ports of the same IP (likely port scanning)
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Yara detected GO Backdoor
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Druid
Status:
Malicious
First seen:
2025-09-17 18:24:18 UTC
File Type:
PE (Dll)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Badlisted process makes network request
Unpacked files
SH256 hash:
2d499700e1319d9203e322cb1e8a8cfec4aa997f86d1fcf76156cfaa0a72054c
MD5 hash:
59c1b29677ef1ac61bc12fec9d8cd816
SHA1 hash:
0f8aafc5808faa6efc4ba8ef98b8880f256fb101
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GOBackdoor

DLL dll 2d499700e1319d9203e322cb1e8a8cfec4aa997f86d1fcf76156cfaa0a72054c

(this sample)

  
Dropped by
ACRStealer
  
Delivery method
Distributed via web download

Comments