MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36bda34a29765be36c30ec657db558dcebc9ed013036f0da2f9f995322922acd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: 36bda34a29765be36c30ec657db558dcebc9ed013036f0da2f9f995322922acd
SHA3-384 hash: 5e73e1c484bec04b620efc94b830dccb7456b99fe833eeb18b59eac467bd28ca46b63c9b7d59cac1af666715e7d991aa
SHA1 hash: c25bf42a824aa11c90425a23ade286cf1bd5a06b
MD5 hash: 741264a0265a67ee70a9ebbf8d94b0fd
humanhash: maryland-network-twelve-crazy
File name:libcurl.dll
Download: download sample
File size:7'485'520 bytes
First seen:2026-07-27 10:12:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d9cdd14f1e51bf231e8fd705275c2c8a
ssdeep 24576:aARinWi2tux0eWmT4kn7vXD6o3sgtcKNEfPB1wQfpiX6ES12OeYao9HLDxp:fiWHlPfkihgwB1i+AYaurD
TLSH T12C767E0CA9DE2C38F31EF4FCC049E5C5ABD7296BCA2641915DE44383D46BEDCA91681E
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 00e8c8d4d4cccc00
Reporter burger
Tags:exe signed

Code Signing Certificate

Organisation:Monitor for Certificate Store
Issuer:Monitor for Certificate Store
Algorithm:sha512WithRSAEncryption
Valid from:2026-07-26T22:45:30Z
Valid to:2031-07-26T22:55:30Z
Serial number: 647063a69b5095ac42ae0e3c4bcd1aa3
Thumbprint Algorithm:SHA256
Thumbprint: 866f20d1b08fbed63a82434b5b5f6459d6ec7bd9c1b89bb33f41022a3b279a66
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
143
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-07-27 10:16:43 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug masquerade mingw overlay packed signed
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-07-27T03:20:00Z UTC
Last seen:
2026-07-27T03:42:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
AI detected suspicious PE / MSI digital signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1948264 Sample: libcurl.dll.exe Startdate: 27/07/2026 Architecture: WINDOWS Score: 60 19 Antivirus / Scanner detection for submitted sample 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 AI detected suspicious PE / MSI digital signature 2->23 7 loaddll64.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 conhost.exe 7->11         started        13 rundll32.exe 7->13         started        15 8 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.DllHijack
Status:
Malicious
First seen:
2026-07-27 08:09:55 UTC
File Type:
PE+ (Dll)
Extracted files:
7
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
36bda34a29765be36c30ec657db558dcebc9ed013036f0da2f9f995322922acd
MD5 hash:
741264a0265a67ee70a9ebbf8d94b0fd
SHA1 hash:
c25bf42a824aa11c90425a23ade286cf1bd5a06b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments