MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a41acf04286e9fb1bdbcc2773c62cfba717bce93a892ecb738792cd014d4ddc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnappyClient


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 3a41acf04286e9fb1bdbcc2773c62cfba717bce93a892ecb738792cd014d4ddc
SHA3-384 hash: 62b15b1a8c91bd05df1a68eea206351873b99d55a38519f74eb3976554e838ee7201da94e46f40bf434d12779bcedfd8
SHA1 hash: 5581cf2ca70bba1ae5e2d7a21da0328464f2e8d4
MD5 hash: ee271237806f726412e7e53507650f3c
humanhash: washington-floor-princess-lamp
File name:UTODYIBG-2.msi
Download: download sample
Signature SnappyClient
File size:8'364'032 bytes
First seen:2026-08-27 19:10:54 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 196608:E3KoUc4BPw8VAzd6Z5ls2DafDN70uL4U2liSJnvsOTN:GnWP2xSgZ70uFQfvsO
TLSH T114863348FEA14B05DCF582B8415A8723771E0CE1BB46D557CA2F727C1A7A2B98BD70E0
TrID 88.4% (.MST) Windows SDK Setup Transform script (61000/1/5)
11.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter aachum
Tags:ClickFix HIjackLoader msi SnappyClient softwareinformsdk-com


Avatar
iamaachum
https://pub-08f0c43713544017a76e18f98cedda63.r2.dev/Phil-Verify-Cloudflare-Challange-v10-M.html => http://uaelos.com/m/2.txt => http://138.124.250.215/n1.txt => http://138.124.250.215/UTODYIBG-2.msi

SnappyClient C2:
softwareinformsdk.com (199.247.18.121:3333)

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-debug crypto fingerprint installer wix
Verdict:
Unknown
File Type:
msi
First seen:
2026-08-28T15:49:00Z UTC
Last seen:
2026-08-28T15:56:00Z UTC
Hits:
~10
Result
Threat name:
HijackLoader, SnappyClient
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
Contains functionality to compare user and computer (likely to detect sandboxes)
Contains functionality to infect the boot sector
Contains VNC / remote desktop functionality (version string found)
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Maps a DLL or memory area into another process
Sample is not signed and drops a device driver
Switches to a custom stack to bypass stack traces
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected HijackLoader
Yara detected SnappyClient
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1964971 Sample: UTODYIBG-2.msi Startdate: 27/08/2026 Architecture: WINDOWS Score: 100 69 Found malware configuration 2->69 71 Antivirus detection for URL or domain 2->71 73 Antivirus detection for dropped file 2->73 75 2 other signatures 2->75 8 msiexec.exe 80 40 2->8         started        12 DriveHyp80.exe 5 2->12         started        14 DriveHyp80.exe 5 2->14         started        16 msiexec.exe 3 2->16         started        process3 file4 51 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32+ 8->51 dropped 53 C:\Users\user\AppData\Local\...\msvcp_win.dll, PE32+ 8->53 dropped 55 C:\Users\user\AppData\Local\...\RfaRpc.dll, PE32+ 8->55 dropped 61 2 other malicious files 8->61 dropped 95 Sample is not signed and drops a device driver 8->95 18 DriveHyp80.exe 7 8->18         started        57 C:\Users\user\AppData\Local\...AF5124.tmp, PE32 12->57 dropped 97 Contains VNC / remote desktop functionality (version string found) 12->97 99 Writes to foreign memory regions 12->99 101 Maps a DLL or memory area into another process 12->101 22 SignalPip.exe 12->22         started        24 memu.exe 12->24         started        59 C:\Users\user\AppData\Local\...F06BC1.tmp, PE32 14->59 dropped 26 SignalPip.exe 14->26         started        28 memu.exe 14->28         started        signatures5 process6 file7 43 C:\ProgramData\...\ucrtbase.dll, PE32+ 18->43 dropped 45 C:\ProgramData\...\msvcp_win.dll, PE32+ 18->45 dropped 47 C:\ProgramData\...\RfaRpc.dll, PE32+ 18->47 dropped 49 2 other malicious files 18->49 dropped 77 Sample is not signed and drops a device driver 18->77 30 DriveHyp80.exe 7 18->30         started        79 Contains VNC / remote desktop functionality (version string found) 22->79 81 Found direct / indirect Syscall (likely to bypass EDR) 22->81 34 WerFault.exe 21 16 22->34         started        36 WerFault.exe 21 26->36         started        signatures8 process9 file10 63 C:\Users\user\AppData\Roaming\...\memu.exe, PE32 30->63 dropped 65 C:\Users\user\AppData\Local\...\SignalPip.exe, PE32 30->65 dropped 67 C:\Users\user\AppData\Local\...\C9B773F.tmp, PE32 30->67 dropped 103 Contains VNC / remote desktop functionality (version string found) 30->103 105 Found hidden mapped module (file has been removed from disk) 30->105 107 Maps a DLL or memory area into another process 30->107 109 Switches to a custom stack to bypass stack traces 30->109 38 SignalPip.exe 30->38         started        41 memu.exe 3 30->41         started        signatures11 process12 signatures13 83 Contains functionality to infect the boot sector 38->83 85 Contains VNC / remote desktop functionality (version string found) 38->85 87 Switches to a custom stack to bypass stack traces 38->87 89 Contains functionality to compare user and computer (likely to detect sandboxes) 38->89 91 Unusual module load detection (module proxying) 41->91 93 Found direct / indirect Syscall (likely to bypass EDR) 41->93
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
CAB:COMPRESSION:LZX Executable Office Document PDB Path PE (Portable Executable) PE File Layout PE Memory-Mapped (Dump)
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-27 19:13:49 UTC
File Type:
Binary (Archive)
Extracted files:
28
AV detection:
4 of 37 (10.81%)
Threat level:
  5/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader credential_access discovery loader persistence privilege_escalation ransomware spyware stealer
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Browser Information Discovery
Enumerates physical storage devices
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Detects HijackLoader (aka IDAT Loader)
Family: HijackLoader, IDAT loader, Ghostulse,
Malware family:
GHOSTPULSE
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SnappyClient

Microsoft Software Installer (MSI) msi 3a41acf04286e9fb1bdbcc2773c62cfba717bce93a892ecb738792cd014d4ddc

(this sample)

Comments