🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e2263f37e3d91b787fdb958435a90f42bddbf21254a1b63fc99172b3ba34b2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Metasploit


Vendor detections: 13


Intelligence 13 IOCs YARA 29 File information Comments

SHA256 hash: 3e2263f37e3d91b787fdb958435a90f42bddbf21254a1b63fc99172b3ba34b2b
SHA3-384 hash: 822b368cb26310dcb7627f0e5b4f46d703190090a25d274765dc0b2201c731218e8c429c2ae8fdb5ad87755165833597
SHA1 hash: 725b5b4410a0f664ebfa66a471b03925267e36eb
MD5 hash: f7562ef5c04f1e5a33e9733e4dcbca59
humanhash: utah-undress-magazine-october
File name:3e2263f37e3d91b787fdb958435a90f42bddbf21254a1b63fc99172b3ba34b2b.exe
Download: download sample
Signature Metasploit
File size:9'030'656 bytes
First seen:2026-09-27 14:10:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 028ba1125164a500ce4a2b589f4eeeec (1 x Metasploit)
ssdeep 196608:jrZENF4dV0CZ/nxXHNlO4Yn5TFUfvmvA0U7mqY5a8EJMdpYpid:j10CZPRH8qfO1HpY
TLSH T108963354979EB7B6E074E832D5F0AD32FEB7D81E78A02846F441B74C74AD510D82CA8E
TrID 52.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.8% (.EXE) Win64 Executable (generic) (6522/11/2)
8.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 0f1769696969330f (1 x Metasploit)
Reporter whack_sh
Tags:exe Metasploit

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-27 14:15:30 UTC
Tags:
upx ip-check

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Creating a file
Creating a file in the Windows directory
Creating a file in the Windows subdirectories
Enabling the 'hidden' option for recently created files
Searching for the window
Creating a process from a recently created file
Creating a process with a hidden window
DNS request
Connection attempt
Launching a service
Changing a file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm aspack base64 crypto hacktool icedid microsoft_visual_cc overlay packed packed packed packer
Verdict:
Malicious
File Type:
exe x32
First seen:
2021-08-22T21:32:00Z UTC
Last seen:
2026-09-28T02:48:00Z UTC
Hits:
~1000
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
50 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
Detected unpacking (changes PE section rights)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has a writeable .text section
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Unusual module load detection (module proxying)
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Backdoor.Poison
Status:
Malicious
First seen:
2021-08-23 16:15:24 UTC
File Type:
PE (Exe)
Extracted files:
39
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
aspackv2 bootkit discovery persistence upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
UPX packed file
Adds Run key to start application
Enumerates connected drives
Writes to the Master Boot Record (MBR)
Checks computer location settings
Executes dropped EXE
Unpacked files
SH256 hash:
3e2263f37e3d91b787fdb958435a90f42bddbf21254a1b63fc99172b3ba34b2b
MD5 hash:
f7562ef5c04f1e5a33e9733e4dcbca59
SHA1 hash:
725b5b4410a0f664ebfa66a471b03925267e36eb
SH256 hash:
a158d20345955c968c072f0f82cf1b2d575fe40629e5d1c70afea808a325703a
MD5 hash:
68672b02794934f8078fc3982931f58f
SHA1 hash:
5e70cac2a522e09336ce0e0849d1e73594672646
SH256 hash:
327f4782711fc71209245a322534d088d16ec47ce302ad305e12ef8b2e84bd88
MD5 hash:
d41abdb962a2510173fa241a4e7a0b31
SHA1 hash:
4e8f0dd16c9102a0c521fdcbc207de1433347252
Detections:
triage_uuloader_loader
SH256 hash:
1fdcd0b4ed2367e0a4469a585ea13c5b5fbbe8913889441f7e705e05835d6d98
MD5 hash:
4aab3638f60c73036e7eb2c359411bc8
SHA1 hash:
ba4d5aad3c808cfb09a2c2d2ae9b5c611ad946be
SH256 hash:
4cc9f81836ce27226f2b4a795a44772148c8515892770e8811411a92298568fb
MD5 hash:
d23614451ec39a4fe0e40d06ea2f4545
SHA1 hash:
51bdcda5d84f8704693fa06b66811803dc71c131
SH256 hash:
ca6d29b99869a95430d72222234161fe79f25e05af65c7e5166debb2e59fff70
MD5 hash:
54843f53001275ffcea0e353a55fec5f
SHA1 hash:
7df15909195a14434fc45e914cd1d64df186af77
Malware family:
BlackMoon
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ASPackv212AlexeySolodovnikov
Author:malware-lu
Rule name:ASProtectV2XDLLAlexeySolodovnikov
Author:malware-lu
Rule name:CMD_Ping_Localhost
Rule name:cobalt_strike_beacon_detected
Author:0x0d4y
Description:This rule detects cobalt strike beacons.
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Hacktools_CN_Panda_andrew
Author:Florian Roth
Description:Disclosed hacktool set - file andrew.exe - sethc.exe Debugger backdoor
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TH_APT_EquationGroup_2026_CYFARE
Author:CYFARE
Description:Equation Group (G0020) APT malware detection - covers EquationDrug, GrayFish, DoubleFantasy, TripleFantasy, Fanny, GROK, nls_933w HDD firmware module, and Shadow Brokers tooling
Reference:https://cyfare.net/
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WIN32_MAL_TROJ_UPATRE_SMBG
Author:Auto-generated rule
Description:Detects UPATRE Trojan variant.
Reference:Not provided
Rule name:Windows_Generic_Threat_3f060b9c
Author:Elastic Security
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks
Rule name:without_attachments
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the no presence of any attachment
Reference:http://laboratorio.blogs.hispasec.com/
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Metasploit

Executable exe 3e2263f37e3d91b787fdb958435a90f42bddbf21254a1b63fc99172b3ba34b2b

(this sample)

  
Delivery method
Distributed via web download

Comments