🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f68027a04d5941ea71e3cdf6b8ddd13ca2bd7fbd15edff7cd44020830da0cb7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 2f68027a04d5941ea71e3cdf6b8ddd13ca2bd7fbd15edff7cd44020830da0cb7
SHA3-384 hash: d8cec6c2709e6d9b806514fc0a1ef6f9fd52ca72ee006d2d53b235ceb3247dbf2e9749f9359002c9bd3975d14215b745
SHA1 hash: fa88c18996d36020919592acd8fa3c9809e09c10
MD5 hash: 46289e98728a5f15c70ca2838d6adb07
humanhash: indigo-king-jig-spring
File name:123.exe
Download: download sample
File size:46'765'056 bytes
First seen:2026-09-29 04:41:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ed8b780a3ce7ca4aba78a21f6bc3d4e0 (10 x OverlordRAT, 9 x VeilStealer, 5 x WailsLoader)
ssdeep 393216:7+jVG97pSExh+aJp1/337KlMk3/cGl/cWXc7uRMEsgbaOlWf+L2r:/p5lx7ycGNI+8
TLSH T168A73953E8D21599C8EFC230D132815BAA71385A4B7C23D71A91F7742F3BBE09AB9741
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-29 04:56:15 UTC
Tags:
sliver golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-29T02:16:00Z UTC
Last seen:
2026-09-29T15:08:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Malware family:
CobaltStrike
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 2f68027a04d5941ea71e3cdf6b8ddd13ca2bd7fbd15edff7cd44020830da0cb7

(this sample)

  
Delivery method
Distributed via web download

Comments