🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e9dbac5402b9b1ece97c6fc54b6ae09447dd2e5584868149eac71a82c679028. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



UnixStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 9 File information Comments

SHA256 hash: 2e9dbac5402b9b1ece97c6fc54b6ae09447dd2e5584868149eac71a82c679028
SHA3-384 hash: c1ab380edee976698009a699a9554349be198dba8f91b41509bd1c5b61c3aeb2bb2628e047be497c3130d9cba7446075
SHA1 hash: 7375c891f34a167e853383e66ad8eb6f0a948882
MD5 hash: 1dc0f32bf189fecc040be8e85ca9a3d3
humanhash: carpet-chicken-illinois-blue
File name:vo.exe
Download: download sample
Signature UnixStealer
File size:261'120 bytes
First seen:2026-09-24 09:36:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:/+RIxU61JA8thit5m4CX92gXgxkDOD5d0Zj/+I/KO2kEijfOrR4Prv2RkS:/yIxlv54spG0xGMK3kEiKGzg
TLSH T19E444B9C8B55EA15D33E07B1EBA11340CBB8C213D946EF461DDB34E0295D74AFA4A0AF
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter smica83
Tags:exe UKR UnixStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
299
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-24 10:40:24 UTC
Tags:
evasion ip-check unixstealer stealer telegram gofile exfiltration attachments attc-unc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Creating a window
Creating a file in the %temp% directory
Deleting a recently created file
Reading critical registry keys
Launching the process to change network settings
Searching for synchronization primitives
Launching a service
Stealing user critical data
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 expand lolbin obfuscated privilege reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-23T09:48:00Z UTC
Last seen:
2026-09-25T06:38:00Z UTC
Hits:
~100
Detections:
PDM:Trojan.Win32.Generic Trojan.Win32.Agent.sb Trojan-PSW.Win32.Coins.sb HEUR:Trojan-PSW.MSIL.Coins.gen Worm.MSIL.Agent.sb Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Agent.sb Trojan-PSW.MSIL.Stealer.sb not-a-virus:PSWTool.MSIL.BroPass.sb
Result
Threat name:
Unix Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Capture Wi-Fi password
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Mail credentials (via file / registry access)
Uses netsh to dump wireless credentials
Uses netsh to modify the Windows network and firewall settings
Uses the Telegram API (likely for C&C communication)
Yara detected Generic Stealer
Yara detected Telegram RAT
Yara detected Unix Stealer
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.37 Win 64 Exe x64
Threat name:
ByteCode-MSIL.Trojan.Zilla
Status:
Malicious
First seen:
2026-09-23 14:39:49 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
1
AV detection:
21 of 36 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
collection discovery persistence privilege_escalation spyware stealer
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Event Triggered Execution: Netsh Helper DLL
System Network Configuration Discovery: Wi-Fi Discovery
Accesses Microsoft Outlook profiles
Checks installed software on the system
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
2e9dbac5402b9b1ece97c6fc54b6ae09447dd2e5584868149eac71a82c679028
MD5 hash:
1dc0f32bf189fecc040be8e85ca9a3d3
SHA1 hash:
7375c891f34a167e853383e66ad8eb6f0a948882
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Lumma_Stealer_Detection
Author:ashizZz
Description:Detects a specific Lumma Stealer malware sample using unique strings and behaviors
Reference:https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/
Rule name:NET
Author:malware-lu
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments