🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c46a3d6f83ce5fc37f328eb80e6cc4121cb41befacc54d2843d15a8a0395b94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mydoom


Vendor detections: 14


Intelligence 14 IOCs YARA 7 File information Comments

SHA256 hash: 3c46a3d6f83ce5fc37f328eb80e6cc4121cb41befacc54d2843d15a8a0395b94
SHA3-384 hash: 65fc116ccc71be95498272f1d75683518a17f7be97e0592984ed7784f31b61078c514ff54eaf11df8f00060b11e928e5
SHA1 hash: 5d9c5afb0ca8406641269fd980e3a3086a818dc8
MD5 hash: 899f8c35499817aa487210462eaf1e42
humanhash: spring-vermont-orange-gee
File name:Qpwwudb.bat
Download: download sample
Signature Mydoom
File size:41'664 bytes
First seen:2026-10-08 06:58:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/vnd.microsoft.portable-executable
imphash 7ee89a85ea0ffd700fd28e6cfa3d968f (4 x MyDoom)
ssdeep 768:Gq9m/ZsybSg2ts4L3RLc/qjhsKmHbk1+qJ0UtH4xIpP:Gqk/Zdic/qjh8w19JDHBP
TLSH T194137C73544095F3C58204706A81EA62AEB9AD771749E343F6D0AB4EECB84C76B3CF06
TrID 39.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
21.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
8.3% (.EXE) Win64 Executable (generic) (6522/11/2)
6.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon b270e0d292c0c482 (85 x Mydoom)
Reporter abuse_ch
Tags:exe Mydoom upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 f3281793c4a06500ca92340714d5726733766f3f1e120fda2eaa64d060dab4ac
File size (compressed) :28'864 bytes
File size (de-compressed) :41'664 bytes
Format:win32/pe
Packed file: f3281793c4a06500ca92340714d5726733766f3f1e120fda2eaa64d060dab4ac

Intelligence


File Origin
# of uploads :
1
# of downloads :
197
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-10-08 07:09:28 UTC
Tags:
mydoom auto-reg upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file in the Windows directory
Creating a process from a recently created file
Creating a process with a hidden window
Searching for the window
Connection attempt
Creating a window
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 evasive masquerade obfuscated obfuscated overlay packed packed reconnaissance services xor-pe xor-pe
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-10-08T04:31:00Z UTC
Last seen:
2026-10-09T20:36:00Z UTC
Hits:
~10
Gathering data
Result
Threat name:
Detection:
malicious
Classification:
spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to many different private IPs (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Drops PE files with benign system names
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found evasive API chain (may stop execution after checking mutex)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Yara detected MyDoom
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1983972 Sample: Qpwwudb.bat.exe Startdate: 08/10/2026 Architecture: WINDOWS Score: 100 39 Antivirus / Scanner detection for submitted sample 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 Yara detected MyDoom 2->43 45 4 other signatures 2->45 6 Qpwwudb.bat.exe 1 5 2->6         started        10 java.exe 1 2->10         started        12 services.exe 2->12         started        process3 file4 25 C:\Windows\services.exe, PE32 6->25 dropped 27 C:\Windows\java.exe, PE32 6->27 dropped 29 C:\Windows\java.exe:Zone.Identifier, ASCII 6->29 dropped 47 Found evasive API chain (may stop execution after checking mutex) 6->47 49 Drops executables to the windows directory (C:\Windows) and starts them 6->49 51 Drops PE files with benign system names 6->51 14 services.exe 1 1 6->14         started        18 WerFault.exe 22 16 6->18         started        31 C:\Users\user\AppData\Local\...\services.exe, PE32 10->31 dropped 53 Antivirus detection for dropped file 10->53 55 Multi AV Scanner detection for dropped file 10->55 57 Exploit detected, runtime environment starts unknown processes 10->57 59 Exploit detected, runtime environment dropped PE file 10->59 21 services.exe 10->21         started        signatures5 process6 dnsIp7 33 192.168.1.10, 1034 unknown unknown 14->33 35 192.168.1.15, 1034 unknown unknown 14->35 37 10 other IPs or domains 14->37 61 Antivirus detection for dropped file 14->61 63 Multi AV Scanner detection for dropped file 14->63 65 Connects to many different private IPs (likely to spread or exploit) 14->65 23 C:\ProgramData\Microsoft\...\Report.wer, Unicode 18->23 dropped file8 signatures9
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Worm.Mydoom
Status:
Malicious
First seen:
2026-10-08 06:59:17 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
37 of 38 (97.37%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mydoom brand:microsoft defense_evasion discovery persistence phishing product:outlook upx worm
Behaviour
Suspicious use of WriteProcessMemory
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Windows directory
UPX packed file
Adds Run key to start application
Executes a file named after a Windows system binary
Executes dropped EXE
Detected microsoft outlook phishing page
Detects MyDoom family
Family: MyDoom
Unpacked files
SH256 hash:
3c46a3d6f83ce5fc37f328eb80e6cc4121cb41befacc54d2843d15a8a0395b94
MD5 hash:
899f8c35499817aa487210462eaf1e42
SHA1 hash:
5d9c5afb0ca8406641269fd980e3a3086a818dc8
Detections:
MyDoom SUSP_XORed_MSDOS_Stub_Message
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_54b0ec47
Author:Elastic Security
Rule name:Windows_Generic_Threat_acf6222b
Author:Elastic Security
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mydoom

Executable exe 3c46a3d6f83ce5fc37f328eb80e6cc4121cb41befacc54d2843d15a8a0395b94

(this sample)

Comments