MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31a4fd8489a1e2d3a3f6fff470d74831f4809ea60a2f0646d56f91a6ff25e7e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 6 File information Comments

SHA256 hash: 31a4fd8489a1e2d3a3f6fff470d74831f4809ea60a2f0646d56f91a6ff25e7e3
SHA3-384 hash: 639a31f06b4f920e5e6d26a06e74a0b56973f24a714cc4482defde1d5c8e7aa6386c28afa592aa7f1cb0984cb14e97ab
SHA1 hash: ccbf36e1950f2d191d6cc477f765948306a54bbf
MD5 hash: f5414b57d1e69295acf4b162d7e4d335
humanhash: william-magnesium-cold-georgia
File name:msedge_elf.dll
Download: download sample
File size:115'712 bytes
First seen:2025-12-23 13:55:38 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f54a16b74f2da8859f059ede3625ef2d
ssdeep 3072:dZ7uHSu1juUDxF8MY4tUOWVzvw8cb6mfuM3inadu1:XK3IUDxF8MY4qOWVzvwHb9d/dy
TLSH T116B3F149B796B4FCCF12E174A0EB9FB6F131F9210A609E3A5188DB786F105465F28473
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10522/11/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Anonymous
Tags:dll exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
donotgroup
ID:
1
File name:
https://1012025shar-secondary.blob.core.windows.net/portal/index.html?id=100
Verdict:
Malicious activity
Analysis date:
2025-12-19 18:16:19 UTC
Tags:
susp-lnk donotgroup apt donot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-debug expand exploit lolbin masquerade packed
Verdict:
Clean
File Type:
dll x64
First seen:
2025-12-23T14:31:00Z UTC
Last seen:
2025-12-23T14:46:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
31a4fd8489a1e2d3a3f6fff470d74831f4809ea60a2f0646d56f91a6ff25e7e3
MD5 hash:
f5414b57d1e69295acf4b162d7e4d335
SHA1 hash:
ccbf36e1950f2d191d6cc477f765948306a54bbf
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_Debugger
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments