MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6
SHA3-384 hash: 39ac1bb7dcd87c5424a3ad8ba01f3f59751378f7ef970d62b6fb5219e48c6b15b5cea50e66ee1ab4c7e97908e5d7c6a5
SHA1 hash: e89c7096f1ff36d5674aa70ac82fc7797ffe9d99
MD5 hash: 9a4970cf9af1e0d83063c43030b3d2a4
humanhash: happy-eighteen-south-stairway
File name:silke.exe
Download: download sample
File size:81'717'184 bytes
First seen:2025-11-30 12:33:40 UTC
Last seen:2026-08-01 21:18:18 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 456c5f4eb288382b62351b047482c783
ssdeep 98304:vM8FuCYsdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdl:rFz
TLSH T13308390E7EDA0602FA7916B43C7E0F9A0BA3E538F01557E3161EEB9CE8511D67E24193
TrID 36.0% (.EXE) Win64 Executable (generic) (10522/11/4)
18.9% (.FON) Windows Font (5545/9/1)
17.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.0% (.ICL) Windows Icons Library (generic) (2059/9)
6.9% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter aachum
Tags:exe signed

Code Signing Certificate

Organisation:{2560B96E-8A14-493C-A129-6C3B4ACF0BE1}
Issuer:{2560B96E-8A14-493C-A129-6C3B4ACF0BE1}
Algorithm:sha1WithRSAEncryption
Valid from:2025-04-17T23:51:28Z
Valid to:2026-04-18T05:51:28Z
Serial number: 44425f8b1a0c62a648437a79fdebbee1
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: bc71c80fb92ab1e38a2e5270f55b26e1913ca22acf7771694a801b667159ed9a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
iamaachum
https://sourceforge.net/projects/stake-crash-predictor/

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
https://limewire.com/d/jnd8k#eifXZXTYHe
Verdict:
Malicious activity
Analysis date:
2025-11-30 12:12:37 UTC
Tags:
arch-exec crypto-regex

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug microsoft_visual_cc signed
Verdict:
Clean
File Type:
PE
First seen:
2025-11-30T10:05:00Z UTC
Last seen:
2025-11-30T10:45:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
AI detected suspicious PE digital signature
Queries temperature or sensor information (via WMI often done to detect virtual machines)
Behaviour
Behavior Graph:
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates connected drives
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6

(this sample)

  
Delivery method
Distributed via web download

Comments