MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 341ab263fc6bd4ce4ddaf6c82132fbfcfe7fc8801def0ccc6dbe2c5f6d071a60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 14 File information Comments

SHA256 hash: 341ab263fc6bd4ce4ddaf6c82132fbfcfe7fc8801def0ccc6dbe2c5f6d071a60
SHA3-384 hash: 1d343d639f32012248742f53f616a319cc822fcadbc43ac8818860ae2abc78721f5e93832c3fefb38f81281c3a9dd176
SHA1 hash: 7bcf7f5da24f159b2fd0003b6301131b9e2c0be5
MD5 hash: b9111cac752e80b064e779d06fbb2bad
humanhash: king-rugby-xray-pizza
File name:SecuriteInfo.com.Win64.MalwareX-gen.77225213
Download: download sample
File size:2'565'120 bytes
First seen:2026-06-03 06:29:14 UTC
Last seen:2026-06-03 07:26:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7d2bd09ae9d9b74185a09a128003b5c1 (1 x ZuqraStealer)
ssdeep 49152:ScIKmjtitHaaNZV/Ovfe/PFJdG5CYUzDC0QOu/r:jAtCHaaHVmv2HFJgAvxe
TLSH T191C5D01AA3B400FCD0B7D2B4CE569907DBB2B8461234969F03D189A62F67B719F3E711
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
156
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-06-03 06:31:56 UTC
Tags:
ip-check evasion github stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect crypted androm virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Modifying an executable file
DNS request
Connection attempt
Sending an HTTP GET request
Sending an HTTP POST request
Creating a file
Launching a process
Sending a custom TCP request
Reading critical registry keys
Сreating synchronization primitives
Changing a file
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Stealing user critical data
Enabling autorun
Forced shutdown of a browser
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm anti-vm cmd crypto expand fingerprint hacktool lolbin microsoft_visual_cc packed reconnaissance
Gathering data
Threat name:
Win64.Malware.Generic
Status:
Suspicious
First seen:
2026-06-03 06:30:54 UTC
File Type:
PE+ (Exe)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Verdict:
suspicious
Label(s):
zuqrastealer
Similar samples:
Result
Malware family:
n/a
Score:
  7/10
Tags:
spyware stealer
Behaviour
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of WriteProcessMemory
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Checks computer location settings
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
341ab263fc6bd4ce4ddaf6c82132fbfcfe7fc8801def0ccc6dbe2c5f6d071a60
MD5 hash:
b9111cac752e80b064e779d06fbb2bad
SHA1 hash:
7bcf7f5da24f159b2fd0003b6301131b9e2c0be5
Malware family:
ChromElevator
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SUSP_ENV_Folder_Root_File_Jan23_1
Author:Florian Roth (Nextron Systems)
Description:Detects suspicious file path pointing to the root of a folder easily accessible via environment variables
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 341ab263fc6bd4ce4ddaf6c82132fbfcfe7fc8801def0ccc6dbe2c5f6d071a60

(this sample)

  
Delivery method
Distributed via web download

Comments