MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6 |
|---|---|
| SHA3-384 hash: | 39ac1bb7dcd87c5424a3ad8ba01f3f59751378f7ef970d62b6fb5219e48c6b15b5cea50e66ee1ab4c7e97908e5d7c6a5 |
| SHA1 hash: | e89c7096f1ff36d5674aa70ac82fc7797ffe9d99 |
| MD5 hash: | 9a4970cf9af1e0d83063c43030b3d2a4 |
| humanhash: | happy-eighteen-south-stairway |
| File name: | silke.exe |
| Download: | download sample |
| File size: | 81'717'184 bytes |
| First seen: | 2025-11-30 12:33:40 UTC |
| Last seen: | 2026-08-01 21:18:18 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 456c5f4eb288382b62351b047482c783 |
| ssdeep | 98304:vM8FuCYsdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdzaG+sdl:rFz |
| TLSH | T13308390E7EDA0602FA7916B43C7E0F9A0BA3E538F01557E3161EEB9CE8511D67E24193 |
| TrID | 36.0% (.EXE) Win64 Executable (generic) (10522/11/4) 18.9% (.FON) Windows Font (5545/9/1) 17.2% (.EXE) Win16 NE executable (generic) (5038/12/1) 7.0% (.ICL) Windows Icons Library (generic) (2059/9) 6.9% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| Reporter | |
| Tags: | exe signed |
Code Signing Certificate
| Organisation: | {2560B96E-8A14-493C-A129-6C3B4ACF0BE1} |
|---|---|
| Issuer: | {2560B96E-8A14-493C-A129-6C3B4ACF0BE1} |
| Algorithm: | sha1WithRSAEncryption |
| Valid from: | 2025-04-17T23:51:28Z |
| Valid to: | 2026-04-18T05:51:28Z |
| Serial number: | 44425f8b1a0c62a648437a79fdebbee1 |
| Intelligence: | 2 malware samples on MalwareBazaar are signed with this code signing certificate |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | bc71c80fb92ab1e38a2e5270f55b26e1913ca22acf7771694a801b667159ed9a |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
Intelligence
File Origin
# of uploads :
2
# of downloads :
108
Origin country :
ESVendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
https://limewire.com/d/jnd8k#eifXZXTYHe
Verdict:
Malicious activity
Analysis date:
2025-11-30 12:12:37 UTC
Tags:
arch-exec crypto-regex
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Clean
Score:
99.9%
Tags:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Unknown
Threat level:
2.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug microsoft_visual_cc signed
Verdict:
Clean
File Type:
PE
First seen:
2025-11-30T10:05:00Z UTC
Last seen:
2025-11-30T10:45:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
AI detected suspicious PE digital signature
Queries temperature or sensor information (via WMI often done to detect virtual machines)
Behaviour
Behavior Graph:
Score:
52%
Verdict:
Susipicious
File Type:
PE
Gathering data
Verdict:
Malicious
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates connected drives
Executes dropped EXE
Verdict:
Malicious
Tags:
n/a
YARA:
n/a
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.