MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 41fc136c41e7d0a88b800fa82ded8145e4fd01e80c1317c96d772cf7b9313b68. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 9
| SHA256 hash: | 41fc136c41e7d0a88b800fa82ded8145e4fd01e80c1317c96d772cf7b9313b68 |
|---|---|
| SHA3-384 hash: | 10679b6db7a64f20f5892ec4acaa84abd6c5bc9b7d2e13e0422f53dacf4eb542e11aeced2f0d4a468366d27fc4c52a11 |
| SHA1 hash: | eb31da8239bad28ee2acb6ed7bd7c7de91355145 |
| MD5 hash: | 15083a24454fd311a411e388256b9d6a |
| humanhash: | burger-oscar-delaware-bravo |
| File name: | svchostplayer.exe |
| Download: | download sample |
| File size: | 94'901'303 bytes |
| First seen: | 2026-07-22 16:32:37 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | cf72283be50852e418ce6bbb6b645835 (7 x BlankGrabber, 1 x CrealStealer, 1 x HawkEye) |
| ssdeep | 1572864:w9z7wSEqWa2TSM+dy2J0f0/rBdsG7bpip0WW7SfK4+K4cNdXXR2vgZUAdT9LUucq:w93rEqxKI5BB7tE0W0474czXRZFL5c |
| TLSH | T1992833192909665EF24C9332E2E1C8677AE334594765C0EA1BD58E4B0FBB1C5FE38C63 |
| TrID | 37.0% (.EXE) Win64 Executable (generic) (6522/11/2) 28.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 11.5% (.EXE) OS/2 Executable (generic) (2029/13) 11.3% (.EXE) Generic Win/DOS Executable (2002/3) 11.3% (.EXE) DOS Executable (generic) (2000/1) |
| Magika | pebin |
| dhash icon | c6c2ccc4f4e0e0f8 (49 x PythonStealer, 28 x SVCStealer, 26 x CoinMiner) |
| Reporter | |
| Tags: | exe eykrqioydzqaehcektgd-supabase-co qvyhijngxiyyxodeoeux-supabase-co |
skocherhan
https://eykrqioydzqaehcektgd.supabase.co/storage/v1/object/public/files/e300ccc0-36ee-4d33-9cc6-c5b52fb0d060/svchostplayer.exeIntelligence
File Origin
# of uploads :
1
# of downloads :
191
Origin country :
GBVendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Creating a window
Running batch commands
Creating a process with a hidden window
Creating a file
Connection attempt
DNS request
Sending a custom TCP request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Setting a single autorun event
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
anti-debug expand installer-heuristic lolbin microsoft_visual_cc overlay packed packed packed pyinstaller pyinstaller reconnaissance
Verdict:
Malicious
Labled as:
QD:Trojan.GenericQ
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-13T21:37:00Z UTC
Last seen:
2026-07-21T04:50:00Z UTC
Hits:
~100
Score:
97%
Verdict:
Malware
File Type:
PE
Gathering data
Threat name:
Win64.Trojan.Ravartar
Status:
Malicious
First seen:
2026-07-13 07:34:07 UTC
File Type:
PE+ (Exe)
Extracted files:
3560
AV detection:
17 of 36 (47.22%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
credential_access execution persistence pyinstaller spyware stealer
Behaviour
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Executes a command shell one-liner
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Drops startup file
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
00c5b29252603ee6c810a1d69ffca491
exe 41fc136c41e7d0a88b800fa82ded8145e4fd01e80c1317c96d772cf7b9313b68
(this sample)
Dropped by
MD5 00c5b29252603ee6c810a1d69ffca491
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.