🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4086fbc79cacbd8bb4c3d915ef1811956c14e5e64a093015ec770c8784078f2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GCleaner


Vendor detections: 10


Intelligence 10 IOCs YARA 8 File information Comments

SHA256 hash: 4086fbc79cacbd8bb4c3d915ef1811956c14e5e64a093015ec770c8784078f2b
SHA3-384 hash: ead149f94a41703627d141821606eb22d6d94172eaf1f2a2520e525b8e4e3491f38479e20611cc4d6ef749cafaedb78b
SHA1 hash: d193e2e7ea095bd5ce4e6d1c07a9d5bf0f4c241f
MD5 hash: b35bae590a171a31a97f37d511024752
humanhash: yankee-six-butter-earth
File name:4086fbc79cacbd8bb4c3d915ef1811956c14e5e64a093015ec770c8784078f2b.exe
Download: download sample
Signature GCleaner
File size:4'815'584 bytes
First seen:2026-09-17 18:33:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 894b3f5e0947a5e27e157493d8a83527 (2 x GCleaner)
ssdeep 98304:zaalk+3U0yXHX3dhsy6bGN3Y7PWhbUMCzFTFzeFfb4wAC:zaalk+3U0uhObGe7uZsnzeFcw1
TLSH T1142633D491168894E257C136D1E406A3A6B8BBF712DA7E3E4637F3530C23EA40EA54F7
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 0000000000000000 (907 x AgentTesla, 573 x Formbook, 316 x RedLineStealer)
Reporter whack_sh
Tags:exe gcleaner

Intelligence


File Origin
# of uploads :
1
# of downloads :
176
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-17 18:39:03 UTC
Tags:
gcleaner loader auto generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug overlay packed packed
Verdict:
Malicious
Labled as:
Win64/GenKryptik_AGeneric.FDJ trojan
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-17T16:11:00Z UTC
Last seen:
2026-09-19T10:39:00Z UTC
Hits:
~100
Result
Threat name:
Amadey, GCleaner, Stealc, Stealc v2
Detection:
malicious
Classification:
spre.troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Detected unpacking (creates a PE file in dynamic memory)
Early bird code injection technique detected
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Powershell creates an autostart link
Queues an APC in another process (thread injection)
Sample uses string decryption to hide its real strings
Sigma detected: Potential Startup Shortcut Persistence Via PowerShell.EXE
Sigma detected: Powershell create lnk in startup
Suricata IDS alerts for network traffic
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Uses known network protocols on non-standard ports
Uses Register-ScheduledTask to add task schedules
Writes to foreign memory regions
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected GCleaner
Yara detected Stealc
Yara detected Stealc v2
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1974475 Sample: VB6tNwmXrE.exe Startdate: 17/09/2026 Architecture: WINDOWS Score: 100 124 45.91.200.135 PODAONLV Netherlands 2->124 126 185.156.73.98 FDN3UA Netherlands 2->126 128 5 other IPs or domains 2->128 156 Suricata IDS alerts for network traffic 2->156 158 Found malware configuration 2->158 160 Antivirus detection for URL or domain 2->160 162 13 other signatures 2->162 12 AutoIt3.exe 1 2->12         started        15 VB6tNwmXrE.exe 3 2->15         started        18 AutoIt3.exe 2->18         started        20 AdvDefragConsole.exe 2->20         started        signatures3 process4 file5 180 Writes to foreign memory regions 12->180 182 Allocates memory in foreign processes 12->182 184 Maps a DLL or memory area into another process 12->184 22 dllhost.exe 29 12->22         started        25 AutoIt3.exe 12->25         started        116 C:\Users\user\AppData\...\8ad284f7_i.exe, PE32 15->116 dropped 27 8ad284f7_i.exe 2 4 15->27         started        186 Antivirus detection for dropped file 18->186 188 Multi AV Scanner detection for dropped file 20->188 signatures6 process7 file8 88 C:\Users\user\AppData\...\7C8bVtLx16.exe, PE32 22->88 dropped 90 C:\Users\user\AppData\...\jRIQdybnxOo.exe, PE32+ 22->90 dropped 92 C:\Users\user\AppData\...\K4PQbYLHJNU9H.exe, PE32+ 22->92 dropped 98 2 other malicious files 22->98 dropped 30 7C8bVtLx16.exe 2 22->30         started        34 6Ph4K1qmO.exe 22->34         started        36 K4PQbYLHJNU9H.exe 22->36         started        43 2 other processes 22->43 94 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32 27->94 dropped 96 C:\Users\user\AppData\...\AttemptIndex.a3x, data 27->96 dropped 172 Antivirus detection for dropped file 27->172 174 Suspicious powershell command line found 27->174 176 Writes to foreign memory regions 27->176 178 3 other signatures 27->178 38 dllhost.exe 23 27->38         started        41 powershell.exe 35 27->41         started        signatures9 process10 dnsIp11 110 C:\Users\user\AppData\...\7C8bVtLx16.tmp, PE32 30->110 dropped 190 Multi AV Scanner detection for dropped file 30->190 45 7C8bVtLx16.tmp 18 26 30->45         started        192 Tries to detect virtualization through RDTSC time measurements 34->192 194 Found direct / indirect Syscall (likely to bypass EDR) 34->194 48 6Ph4K1qmO.exe 34->48         started        52 K4PQbYLHJNU9H.exe 36->52         started        132 91.92.242.236, 49724, 49726, 80 OMEGATECH-ASSC Netherlands 38->132 134 drive.usercontent.google.com 192.178.231.132, 443, 49723, 49725 GOOGLE-GoogleLLCUS United States 38->134 112 C:\Users\user\AppData\...\XPti8DRNandw.exe, PE32 38->112 dropped 114 C:\Users\user\AppData\...\mOC91peSfs0.exe, PE32+ 38->114 dropped 196 Unusual module load detection (module proxying) 38->196 54 mOC91peSfs0.exe 38->54         started        56 XPti8DRNandw.exe 38->56         started        198 Found many strings related to Crypto-Wallets (likely being stolen) 41->198 200 Powershell creates an autostart link 41->200 202 Loading BitLocker PowerShell Module 41->202 58 conhost.exe 41->58         started        60 conhost.exe 43->60         started        62 conhost.exe 43->62         started        file12 signatures13 process14 dnsIp15 102 C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32 45->102 dropped 104 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 45->104 dropped 106 C:\Users\user\AppData\Local\...\_iscrypt.dll, PE32 45->106 dropped 108 21 other malicious files 45->108 dropped 64 AdvDefragConsole.exe 3 45->64         started        118 proxy.mailverifycenter.com 194.59.31.160 VIRTUO-12651980CANADAINCCA France 48->118 136 Early bird code injection technique detected 48->136 138 Queues an APC in another process (thread injection) 48->138 140 Injects a PE file into a foreign processes 48->140 142 Found direct / indirect Syscall (likely to bypass EDR) 48->142 67 chrome.exe 48->67         started        120 185.177.239.241 NEONCORENETWORKSUS Sweden 52->120 144 Injects code into the Windows Explorer (explorer.exe) 54->144 146 Writes to foreign memory regions 54->146 148 Allocates memory in foreign processes 54->148 150 Creates a thread in another existing process (thread injection) 54->150 69 explorer.exe 54->69 injected 152 Multi AV Scanner detection for dropped file 56->152 154 Detected unpacking (creates a PE file in dynamic memory) 56->154 file16 signatures17 process18 dnsIp19 84 C:\ProgramData\...\AdvDefragConsole.exe, PE32 64->84 dropped 73 powershell.exe 64->73         started        130 wosback.cc 104.21.68.208 CLOUDFLARENET-CloudflareIncUS Canada 69->130 164 System process connects to network (likely due to code injection or exploit) 69->164 166 Found many strings related to Crypto-Wallets (likely being stolen) 69->166 168 Tries to harvest and steal browser information (history, passwords, etc) 69->168 170 Tries to steal Crypto Currency Wallets 69->170 76 chrome.exe 69->76         started        file20 signatures21 process22 file23 100 C:\Users\user\...\AdvDefragConsole32.lnk, MS 73->100 dropped 78 conhost.exe 73->78         started        80 chrome.exe 76->80         started        process24 dnsIp25 122 www.google.com 142.251.157.119 GOOGLE-GoogleLLCUS United States 80->122 86 Chrome Cache Entry: 148, PDP-11 80->86 dropped file26
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Executes dropped EXE
Unpacked files
SH256 hash:
4086fbc79cacbd8bb4c3d915ef1811956c14e5e64a093015ec770c8784078f2b
MD5 hash:
b35bae590a171a31a97f37d511024752
SHA1 hash:
d193e2e7ea095bd5ce4e6d1c07a9d5bf0f4c241f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GCleaner

Executable exe 4086fbc79cacbd8bb4c3d915ef1811956c14e5e64a093015ec770c8784078f2b

(this sample)

  
Delivery method
Distributed via web download

Comments