MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 300d00cc110e0ccc17e74599de80076085a58741fe73772ef6fcb0167c0d64c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: 300d00cc110e0ccc17e74599de80076085a58741fe73772ef6fcb0167c0d64c5
SHA3-384 hash: a051886c96fbac645a3b5cc37da33ab05ecea1fd060812af596b510294085644b6d616efa47cfa51f7c3bc89ff7c1195
SHA1 hash: 9df9c86469e912d1c28454bc5853003be287806b
MD5 hash: 250e0703d15cb9896c6ca786164232db
humanhash: cup-beryllium-delta-london
File name:intl.dll
Download: download sample
File size:111'616 bytes
First seen:2026-07-04 09:37:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1b5b5b4032908bbd119ef7f7d2031445 (2 x SilentNet)
ssdeep 1536:ZPJlpPpUI1cuSvOKtUDLH1OF/y0uwmb7AOrKWzqgTYrP3nWWkDKpFCMpPzKfm:n3Z1i+kK0DSAObqgYWwpFCMp+e
TLSH T16DB30247E9E252DAC986263E0A879F61E965BE30479113E33531F02E1EF1AD42CF9570
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter burger
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
130
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
https://gofile.io/d/Jr83uo
Verdict:
Malicious activity
Analysis date:
2026-07-03 18:02:24 UTC
Tags:
arch-exec fileshare auto generic susp-powershell silentnet stealer etherhiding python arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expand lolbin masquerade packed
Result
Threat name:
EtherHiding
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Powershell drops PE file
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Windows Binaries Write Suspicious Extensions
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Yara detected EtherHiding
Yara detected Powershell decode and execute
Yara detected Python Decrypt and Execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1937426 Sample: intl.dll.exe Startdate: 04/07/2026 Architecture: WINDOWS Score: 100 66 www.python.org 2->66 68 thisisafalsepositive.st 2->68 70 7 other IPs or domains 2->70 80 Suricata IDS alerts for network traffic 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 Antivirus detection for URL or domain 2->84 86 11 other signatures 2->86 9 loaddll64.exe 2 2->9         started        signatures3 process4 file5 50 C:\Users\user\AppData\Local\...\b5138843.ps1, ASCII 9->50 dropped 90 Suspicious powershell command line found 9->90 13 rundll32.exe 1 9->13         started        17 rundll32.exe 1 9->17         started        19 rundll32.exe 1 9->19         started        21 33 other processes 9->21 signatures6 process7 file8 52 C:\Users\user\AppData\Local\...\00eb8355.ps1, ASCII 13->52 dropped 92 Suspicious powershell command line found 13->92 23 powershell.exe 14 19 13->23         started        28 WerFault.exe 23 18 13->28         started        54 C:\Users\user\AppData\Local\...\00744376.ps1, ASCII 17->54 dropped 30 powershell.exe 17->30         started        56 C:\Users\user\AppData\Local\...\d142766c.ps1, ASCII 19->56 dropped 94 Bypasses PowerShell execution policy 19->94 58 C:\Users\user\AppData\Local\...\fc11e198.ps1, ASCII 21->58 dropped 60 C:\Users\user\AppData\Local\...\f1907451.ps1, ASCII 21->60 dropped 62 C:\Users\user\AppData\Local\...\df0ebc35.ps1, ASCII 21->62 dropped 64 17 other malicious files 21->64 dropped 32 rundll32.exe 1 21->32         started        34 conhost.exe 21->34         started        36 powershell.exe 21->36         started        signatures9 process10 dnsIp11 72 rpc-mainnet.matic.quiknode.pro 150.136.141.142, 443, 49711, 49719 ORACLE-BMC-31898-OracleCorporationUS United States 23->72 74 polygon-rpc.com 198.178.224.35, 443, 49707, 49716 LATITUDE-SH-LatitudeshUS United States 23->74 78 3 other IPs or domains 23->78 42 C:\Users\user\AppData\Local\...\get-pip.py, Python 23->42 dropped 88 Powershell drops PE file 23->88 38 conhost.exe 23->38         started        76 mr-b01.tm-azurefd.net 150.171.109.73, 443, 49706, 49708 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 28->76 44 C:\Users\user\AppData\Local\...\app.pyd, PE32+ 30->44 dropped 46 C:\Users\user\AppData\Local\...\main.py, Python 30->46 dropped 40 conhost.exe 30->40         started        48 C:\Users\user\AppData\Local\...\dea0cc2e.ps1, ASCII 32->48 dropped file12 signatures13 process14
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Packed.Generic
Status:
Suspicious
First seen:
2026-07-03 21:29:56 UTC
File Type:
PE+ (Dll)
AV detection:
17 of 24 (70.83%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
credential_access defense_evasion discovery execution persistence privilege_escalation spyware stealer
Behaviour
Modifies data under HKEY_USERS
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Event Triggered Execution: Netsh Helper DLL
ConfuserEx .NET packer
Drops file in System32 directory
Accesses cryptocurrency files/wallets, possible credential harvesting
Executes dropped EXE
Loads dropped DLL
Reads data files stored by FTP clients
Reads ssh keys stored on the system
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Modifies Windows Firewall
Unpacked files
SH256 hash:
300d00cc110e0ccc17e74599de80076085a58741fe73772ef6fcb0167c0d64c5
MD5 hash:
250e0703d15cb9896c6ca786164232db
SHA1 hash:
9df9c86469e912d1c28454bc5853003be287806b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments