MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 39c4d5fa49fbd60a79d81d530c51ec308030bb29cd7e5ff3e618c51f1c252dd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
DarkCloud
Vendor detections: 17
| SHA256 hash: | 39c4d5fa49fbd60a79d81d530c51ec308030bb29cd7e5ff3e618c51f1c252dd9 |
|---|---|
| SHA3-384 hash: | 4cfd2777a642ce36e033914738477d4b0a82d5f8c1364c101277032f7452e21d5c6f22893f04c1a3b604f585edec5926 |
| SHA1 hash: | d072b0127213128dfd2f1e11424570f70b7bb933 |
| MD5 hash: | db972e8a15ffb1de154b4cfbcfad73bf |
| humanhash: | romeo-jupiter-eleven-utah |
| File name: | CP.SA.F.16 FIYAT TALEBI TEKNIK 29.10.2025.exe |
| Download: | download sample |
| Signature | DarkCloud |
| File size: | 708'608 bytes |
| First seen: | 2025-10-29 15:57:17 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:/5WNfE3HRBiKCE76mhscR5NaZ58zN9gQ2kkJ7HdspcTh++NGmqp:c23HLCqjDRMtQzW796cT8+NGmu |
| Threatray | 3'637 similar samples on MalwareBazaar |
| TLSH | T192E412507B15C603D2AA6BB66861E17113B8BE5EB820E3569FD57EEF7271F004C48B23 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | a310logger DarkCloud exe geo TUR |
Intelligence
File Origin
SEVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
9c8dc33044496391d8c628943ce78fb909a2cf544a9cd123d0f35fb12d8440f7
a42530d23d10ce4fb58b72111a6d09c6122dca4ff9fe56550d8e5acbacaab5f2
b8e61acf85a2a2cd74273924522f735464171c456f707d4b3b7355b629d589bb
39c4d5fa49fbd60a79d81d530c51ec308030bb29cd7e5ff3e618c51f1c252dd9
7069a9faee825abe7fc570c46b7bcef667d59e4f81373080bb43d70784b6338c
0f0b63fe9635a5c073fb6a2e2170fe529a987607638dfcfe3976b489adf4aa2c
57378c33c553ef97323e0677db7e0bf0e87659e9d3c37f54a4057734c928b344
5714f6c207905edfabe28d25cf45f9ad3ccd7cab643b1b61001b93a38366096c
b3c88415963de8d3885dfb1f8f6ac107ff8ee35881bcd0ec48c196fac52a2bad
b7683fd7199b2427967b10d7194e78645ecab9dad2adb0fc4d5b61937a8847a1
2324345de734b61a39e3fa871f9d053960df279a646e73826a0619dc32eb5169
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.