🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 370e9997a6a7ffd23a7601e52a2253b791c7bce3a2b5855cd51ff363cceae0b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GCleaner


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 370e9997a6a7ffd23a7601e52a2253b791c7bce3a2b5855cd51ff363cceae0b9
SHA3-384 hash: 095c4aaea6ecf661956d515e5f620f991cc775d66d1bf0996ca6179926b17d8075472480b98f5792e74522f458b1aa01
SHA1 hash: 4f1f31bb8884b6778396cfa743f28b7b1a99b41a
MD5 hash: 08780d0ed22289c5e70ef6823cc65ea9
humanhash: bulldog-fillet-sink-charlie
File name:setup_euone.bin
Download: download sample
Signature GCleaner
File size:3'451'624 bytes
First seen:2026-09-17 16:52:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 894b3f5e0947a5e27e157493d8a83527 (2 x GCleaner)
ssdeep 98304:H6A/jgPKHqsZ5Eeglx1R96po9lWSaKb01eksLh:VcPKqESeglxJ6u9lBt00J
TLSH T1FBF5338D90FA85BFC0E208B1BD4AD12394BA711D1D59CCB438AC5B773492A92E723DDD
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 0000000000000000 (907 x AgentTesla, 573 x Formbook, 316 x RedLineStealer)
Reporter aachum
Tags:dropped-by-OffLoader exe gcleaner


Avatar
iamaachum
http://91.92.242.236/setup?name=euone

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-17 17:12:19 UTC
Tags:
gcleaner loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug masquerade overlay packed packed
Verdict:
Malicious
Labled as:
Win64/GenKryptik_AGeneric.FDJ trojan
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-17T16:41:00Z UTC
Last seen:
2026-09-19T06:12:00Z UTC
Hits:
~100
Result
Threat name:
GCleaner
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Found malware configuration
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses Register-ScheduledTask to add task schedules
Writes to foreign memory regions
Yara detected GCleaner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1974439 Sample: setup_euone.bin.exe Startdate: 17/09/2026 Architecture: WINDOWS Score: 100 39 45.91.200.135 PODAONLV Netherlands 2->39 41 185.156.73.98 FDN3UA Netherlands 2->41 43 drive.usercontent.google.com 2->43 57 Found malware configuration 2->57 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected GCleaner 2->61 63 2 other signatures 2->63 9 setup_euone.bin.exe 3 2->9         started        12 AutoIt3.exe 1 2->12         started        15 AutoIt3.exe 2->15         started        signatures3 process4 file5 37 C:\Users\user\AppData\...\f2b1878a_i.exe, PE32 9->37 dropped 17 f2b1878a_i.exe 2 4 9->17         started        69 Writes to foreign memory regions 12->69 71 Allocates memory in foreign processes 12->71 73 Maps a DLL or memory area into another process 12->73 21 dllhost.exe 12 12->21         started        23 AutoIt3.exe 12->23         started        75 Antivirus detection for dropped file 15->75 signatures6 process7 file8 33 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32 17->33 dropped 35 C:\Users\user\AppData\...\DiseaseMinistry.a3x, data 17->35 dropped 49 Antivirus detection for dropped file 17->49 51 Suspicious powershell command line found 17->51 53 Writes to foreign memory regions 17->53 55 3 other signatures 17->55 25 powershell.exe 37 17->25         started        28 dllhost.exe 12 17->28         started        signatures9 process10 dnsIp11 65 Loading BitLocker PowerShell Module 25->65 31 conhost.exe 25->31         started        45 91.92.242.236, 49721, 49723, 80 OMEGATECH-ASSC Netherlands 28->45 47 drive.usercontent.google.com 172.217.75.132, 443, 49720, 49722 GOOGLE-GoogleLLCUS United States 28->47 67 Unusual module load detection (module proxying) 28->67 signatures12 process13
Gathering data
Threat name:
Win64.Trojan.Tepfer
Status:
Suspicious
First seen:
2026-09-17 16:52:23 UTC
File Type:
PE+ (Exe)
Extracted files:
7
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Executes dropped EXE
Unpacked files
SH256 hash:
370e9997a6a7ffd23a7601e52a2253b791c7bce3a2b5855cd51ff363cceae0b9
MD5 hash:
08780d0ed22289c5e70ef6823cc65ea9
SHA1 hash:
4f1f31bb8884b6778396cfa743f28b7b1a99b41a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GCleaner

Executable exe 370e9997a6a7ffd23a7601e52a2253b791c7bce3a2b5855cd51ff363cceae0b9

(this sample)

  
Delivery method
Distributed via web download

Comments