🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3bb3ccf1f9cb1ce51944f5968e2f07d548853b931e9863ba52f7b680c964054f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 7 File information Comments

SHA256 hash: 3bb3ccf1f9cb1ce51944f5968e2f07d548853b931e9863ba52f7b680c964054f
SHA3-384 hash: b676b7d388efa7d1233320945316be6f2decfefc625a404a2e77fd537d55656e454f29fb2f1f586def51c81f03dc5d22
SHA1 hash: c25836bdf16b49f528460bdb927072c47272ff39
MD5 hash: d29cde7edf28ee35408e3280cae90a0c
humanhash: low-fourteen-edward-lactose
File name:3bb3ccf1f9cb1ce5.bin
Download: download sample
File size:2'132'080 bytes
First seen:2026-09-27 13:25:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (26 x ValleyRAT, 20 x OffLoader, 14 x Tofsee)
ssdeep 24576:hXNrSLScusMmOvjjhzvL3kYVgkcXjPeynRkIegf+Sve+9Cx+gBbfWzOUxSXc64dM:6uI2h7HcTeynRkfg7ve+AhrWzOUG
TLSH T1DEA5D03FB28B653EE06E5A3A79B2E110583B7A6165138C5696F4C88CCF254701E3F787
TrID 63.8% (.EXE) Inno Setup installer (107240/4/30)
24.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.8% (.EXE) Win64 Executable (generic) (6522/11/2)
2.6% (.EXE) Win32 Executable (generic) (4504/4/1)
1.2% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon b36494a8cca2cc4d (6 x RedLineStealer, 1 x RaccoonStealer)
Reporter whack_sh
Tags:exe signed

Code Signing Certificate

Organisation:SOFTONIC INTERNATIONAL SA
Issuer:Sectigo Public Code Signing CA EV R36
Algorithm:sha256WithRSAEncryption
Valid from:2026-01-28T00:00:00Z
Valid to:2027-01-28T23:59:59Z
Serial number: c3607b2510e7ab39ff16c1998bbf0c85
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: b1e1dbb1624601638e698d1bf0c4e080eb335e6fb4dd29df68ab6951a96452e7
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-27 13:35:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Adware
File Type:
exe x32
First seen:
2026-09-28T18:06:00Z UTC
Last seen:
2026-09-28T18:25:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.spyw.evad.troj
Score:
48 / 100
Signature
Contains functionality to infect the boot sector
Creates a FSFilter Anti-Virus service
Creates an undocumented autostart registry key
Creates multiple autostart registry keys
Detected potential unwanted application
Enables network access during safeboot for specific services
Found API chain indicative of debugger detection
Installs a global event hook (focus changed)
Multi AV Scanner detection for submitted file
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal browser information (history, passwords, etc)
Writes many files with high entropy
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1978664 Sample: 3bb3ccf1f9cb1ce5.bin.exe Startdate: 27/09/2026 Architecture: WINDOWS Score: 48 169 shepherd.avcdn.net 2->169 171 images.sftcdn.net 2->171 173 34 other IPs or domains 2->173 205 Multi AV Scanner detection for submitted file 2->205 207 Detected potential unwanted application 2->207 209 Tries to delay execution (extensive OutputDebugStringW loop) 2->209 13 3bb3ccf1f9cb1ce5.bin.exe 2 2->13         started        16 bgapp.exe 2->16         started        20 svchost.exe 14 2->20         started        22 2 other processes 2->22 signatures3 process4 dnsIp5 141 C:\Users\user\...\3bb3ccf1f9cb1ce5.bin.tmp, PE32 13->141 dropped 24 3bb3ccf1f9cb1ce5.bin.tmp 5 23 13->24         started        159 23.186.168.128 MAXHOST-IO-AmazingCreationsandMoreLLCUS United States 16->159 161 23.186.168.131 MAXHOST-IO-AmazingCreationsandMoreLLCUS United States 16->161 163 3 other IPs or domains 16->163 201 Tries to harvest and steal browser information (history, passwords, etc) 16->201 29 WerFault.exe 20->29         started        31 WerFault.exe 20->31         started        file6 signatures7 process8 dnsIp9 183 151.101.1.91, 443, 49734, 49735 FASTLY-FastlyIncUS Canada 24->183 185 swls.map.fastly.net 151.101.193.91, 443, 49725 FASTLY-FastlyIncUS Canada 24->185 187 d2it9arwsniqaq.cloudfront.net 99.84.169.140, 443, 49719, 49723 AMAZON-02-AmazoncomIncUS United States 24->187 127 C:\Users\...\cookie_mmm_irs_ppi_008_585.exe, PE32 24->127 dropped 129 C:\Users\user\...\component0.zip (copy), Zip 24->129 dropped 131 C:\Users\user\AppData\...\component0 (copy), Zip 24->131 dropped 133 2 other files (none is malicious) 24->133 dropped 225 Writes many files with high entropy 24->225 33 cookie_mmm_irs_ppi_008_585.exe 6 42 24->33         started        38 OperaSetup.exe 2 24->38         started        40 WerFault.exe 24->40         started        42 WerFault.exe 24->42         started        file10 signatures11 process12 dnsIp13 165 analytics-prod.tf.ff.avast.com 34.117.223.223, 443, 49738, 49740 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 33->165 167 e337078.dscd.akamaiedge.net 23.44.131.203, 443, 49739 AKAMAI-ASN1NL United States 33->167 99 C:\Windows\Temp\...\icarus.exe, PE32+ 33->99 dropped 101 C:\Windows\Temp\...\setupui.cont, XZ 33->101 dropped 103 C:\...\ad9ea76e-42ab-4e8b-b4d6-4ade76decaf1, LZMA 33->103 dropped 107 9 other files (5 malicious) 33->107 dropped 211 Contains functionality to infect the boot sector 33->211 213 Writes many files with high entropy 33->213 44 icarus.exe 33->44         started        105 C:\Users\user\AppData\Local\...\installer.exe, PE32+ 38->105 dropped 49 installer.exe 82 38->49         started        file14 signatures15 process16 dnsIp17 189 analytics.avcdn.net 44->189 191 lb-shepherd-prod.tf.ff.avast.com 34.160.176.28, 443, 49757 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 44->191 197 3 other IPs or domains 44->197 143 C:\Windows\Temp\...\icarus_rvrt.exe, PE32+ 44->143 dropped 145 C:\Windows\Temp\...\icarus_product.dll, PE32+ 44->145 dropped 147 C:\Windows\Temp\...\icarus.exe, PE32+ 44->147 dropped 155 13 other files (8 malicious) 44->155 dropped 231 Writes many files with high entropy 44->231 51 icarus.exe 44->51         started        55 icarus.exe 44->55         started        193 lati.lb.opera.technology 107.167.110.211, 443, 49745 OPERASOFTWARE-OperaSoftwareAmericasLLCUS United States 49->193 195 submit-trn.osp.opera.software 107.167.125.189, 443, 49743, 49744 OPERASOFTWARE-OperaSoftwareAmericasLLCUS United States 49->195 199 6 other IPs or domains 49->199 149 C:\Users\user\AppData\Local\...\opera_package, PE32 49->149 dropped 151 de932af914ba00303d...831101e2.crx (copy), Google 49->151 dropped 153 C:\Users\...\77EC63BDA74BD0D0E0426DC8F8008506, Microsoft 49->153 dropped 157 3 other files (none is malicious) 49->157 dropped 233 Found API chain indicative of debugger detection 49->233 58 installer.exe 49->58         started        60 Assistant_136.0.6008.52_Setup.exe_sfx.exe 49->60         started        62 assistant_installer.exe 49->62         started        64 2 other processes 49->64 file18 signatures19 process20 dnsIp21 109 C:\...\snxhk.dll.ipending.801cf9b5, PE32 51->109 dropped 111 C:\...\gaming_hook.exe.ipending.801cf9b5, PE32 51->111 dropped 113 C:\...\dnd_helper.dll.ipending.801cf9b5, PE32 51->113 dropped 119 316 other files (197 malicious) 51->119 dropped 215 Creates an undocumented autostart registry key 51->215 217 Creates multiple autostart registry keys 51->217 219 Enables network access during safeboot for specific services 51->219 221 Creates a FSFilter Anti-Virus service 51->221 66 AvEmUpdate.exe 51->66         started        69 AvEmUpdate.exe 51->69         started        181 23.44.203.22 AKAMAI-ASN1NL United States 55->181 121 173 other files (138 malicious) 55->121 dropped 223 Writes many files with high entropy 55->223 71 engsup.exe 55->71         started        115 C:\Users\user\AppData\Local\...\installer.exe, PE32+ 58->115 dropped 123 23 other files (5 malicious) 58->123 dropped 73 installer.exe 58->73         started        77 installer.exe 58->77         started        117 C:\Users\user\...\assistant_installer.exe, PE32 60->117 dropped 125 3 other files (none is malicious) 60->125 dropped 79 assistant_installer.exe 62->79         started        file22 signatures23 process24 dnsIp25 175 34.111.175.102 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 66->175 177 23.44.131.146 AKAMAI-ASN1NL United States 66->177 179 23.44.131.153 AKAMAI-ASN1NL United States 66->179 135 C:\Users\user\AppData\Local\...\opera.exe, PE32+ 73->135 dropped 137 C:\Users\user\...\opera_autoupdate.exe, PE32+ 73->137 dropped 139 opera_autoupdate.e...90523960.old (copy), PE32+ 73->139 dropped 227 Installs a global event hook (focus changed) 73->227 229 Tries to detect sandboxes / dynamic malware analysis system (Installed program check) 73->229 81 assistant_installer.exe 73->81         started        85 installer.exe 73->85         started        file26 signatures27 process28 file29 91 C:\Users\user\AppData\Local\...\dbghelp.dll, PE32 81->91 dropped 93 C:\Users\user\AppData\Local\...\dbgcore.dll, PE32 81->93 dropped 95 C:\Users\user\...\browser_assistant.exe, PE32 81->95 dropped 97 C:\Users\user\...\assistant_installer.exe, PE32 81->97 dropped 203 Creates multiple autostart registry keys 81->203 87 assistant_installer.exe 81->87         started        89 assistant_installer.exe 81->89         started        signatures30 process31
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.OfferCore
Status:
Suspicious
First seen:
2026-09-09 20:13:34 UTC
File Type:
PE (Exe)
Extracted files:
7
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
bootkit defense_evasion discovery installer persistence spyware stealer trojan
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Modifies system certificate store
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in System32 directory
Checks for any installed AV software in registry
Checks installed software on the system
Enumerates connected drives
Writes to the Master Boot Record (MBR)
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Writes a Windows system DLL name to a user directory
Downloads MZ/PE file
Uses Session Manager for persistence
Unpacked files
SH256 hash:
3bb3ccf1f9cb1ce51944f5968e2f07d548853b931e9863ba52f7b680c964054f
MD5 hash:
d29cde7edf28ee35408e3280cae90a0c
SHA1 hash:
c25836bdf16b49f528460bdb927072c47272ff39
SH256 hash:
396fec22d27d44772640a5be90f3438235b27f17cf69e6dc88b60bf9c539782b
MD5 hash:
394ef3455c01fbdd41bbc1445bb24b4c
SHA1 hash:
8a758ce3768685d575de209c64d0bd8ae5ebbb0b
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 3bb3ccf1f9cb1ce51944f5968e2f07d548853b931e9863ba52f7b680c964054f

(this sample)

  
Delivery method
Distributed via web download

Comments