MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 42d00bbf109d84bf076159af48932d3354d76daecf049fd09559dba48d3b5d21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZigClipper


Vendor detections: 11


Intelligence 11 IOCs YARA 18 File information Comments

SHA256 hash: 42d00bbf109d84bf076159af48932d3354d76daecf049fd09559dba48d3b5d21
SHA3-384 hash: 383a82b81dbbf79bb4cc92390e05aac5ab925dd21d43f622bee119718a01fa552f5f9e337fcdc5d8c73b60f56fb27d6b
SHA1 hash: 228f0bddad60a54084c91a8703d346bafb95e16d
MD5 hash: e8a57773a2cbc39610a3707a175e02ac
humanhash: mockingbird-golf-shade-lima
File name:gd.dll
Download: download sample
Signature ZigClipper
File size:7'767'896 bytes
First seen:2026-08-05 11:39:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 38423d1725d9d93a9af5427aac0c4e07 (1 x ZigClipper)
ssdeep 49152:d8ipm4YoewYd3PKK4MZYWqvZaqZOEFbXCixPCpLzaR9FgprrawwMWyZZSPUP8Ijj:iJpNZYWyZHTC2s
TLSH T149769E0BFD6A58DFD69EB034502372157F213C004666276769E0F3382E33769A5EEB29
TrID 56.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
22.4% (.EXE) Win64 Executable (generic) (6522/11/2)
6.9% (.EXE) OS/2 Executable (generic) (2029/13)
6.8% (.EXE) Generic Win/DOS Executable (2002/3)
6.8% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter threatcat_ch
Tags:ACRStealer AnimateClipper ClearFake exe ZigClipper

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
https://sietefarma.com/
Verdict:
Malicious activity
Analysis date:
2026-07-29 15:43:32 UTC
Tags:
evasion etherhiding clickfix phishing webdav golang loader stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto masquerade signed
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-07-30T04:01:00Z UTC
Last seen:
2026-08-06T09:25:00Z UTC
Hits:
~100
Detections:
Trojan.Win64.DLLhijack.gck
Result
Threat name:
ACR Stealer, ZigClipper
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
AI detected suspicious PE / MSI digital signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Creates autostart registry keys to launch java
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sigma detected: RunDLL32 Spawning Explorer
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected ACR Stealer
Yara detected ZigClipper
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1952641 Sample: gd.dll.exe Startdate: 05/08/2026 Architecture: WINDOWS Score: 100 109 lb.propertyfind.cc 2->109 111 aaf0e58824b44ab71.awsglobalaccelerator.com 2->111 113 bsc.rpc.blxrbdn.com 2->113 133 Suricata IDS alerts for network traffic 2->133 135 Antivirus detection for dropped file 2->135 137 Antivirus / Scanner detection for submitted sample 2->137 139 7 other signatures 2->139 10 loaddll64.exe 1 2->10         started        12 cmd.exe 2->12         started        14 cmd.exe 2->14         started        signatures3 process4 process5 16 rundll32.exe 10->16         started        18 rundll32.exe 10->18         started        20 cmd.exe 1 10->20         started        31 3 other processes 10->31 22 java.exe 12->22         started        25 conhost.exe 12->25         started        27 java.exe 14->27         started        29 conhost.exe 14->29         started        signatures6 33 explorer.exe 8 16->33         started        38 explorer.exe 18->38         started        40 rundll32.exe 20->40         started        171 Injects code into the Windows Explorer (explorer.exe) 22->171 173 Writes to foreign memory regions 22->173 175 Allocates memory in foreign processes 22->175 42 conhost.exe 22->42         started        44 explorer.exe 22->44         started        177 Modifies the context of a thread in another process (thread injection) 27->177 179 Injects a PE file into a foreign processes 27->179 46 conhost.exe 27->46         started        48 explorer.exe 27->48         started        process7 dnsIp8 101 8.8.8.8, 443, 49720, 49722 GOOGLE-GoogleLLCUS United States 33->101 103 dist.vertexengine.cc 104.21.60.218, 443, 49721, 49726 CLOUDFLARENET-CloudflareIncUS Canada 33->103 107 2 other IPs or domains 33->107 77 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 33->77 dropped 79 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 33->79 dropped 81 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32+ 33->81 dropped 89 3 other malicious files 33->89 dropped 141 System process connects to network (likely due to code injection or exploit) 33->141 143 Tries to harvest and steal browser information (history, passwords, etc) 33->143 145 Tries to steal Crypto Currency Wallets 33->145 147 Switches to a custom stack to bypass stack traces 33->147 50 java.exe 33->50         started        54 chrome.exe 33->54         started        105 dist.vertexengine.cc 38->105 83 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 38->83 dropped 85 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 38->85 dropped 87 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32+ 38->87 dropped 91 3 other malicious files 38->91 dropped 149 Found direct / indirect Syscall (likely to bypass EDR) 38->149 56 java.exe 38->56         started        58 chrome.exe 38->58         started        60 explorer.exe 40->60         started        file9 signatures10 process11 dnsIp12 93 C:\ProgramData\megami\vcruntime140_1.dll, PE32+ 50->93 dropped 95 C:\ProgramData\megami\vcruntime140.dll, PE32+ 50->95 dropped 97 C:\ProgramData\megami\ucrtbase.dll, PE32+ 50->97 dropped 99 3 other malicious files 50->99 dropped 151 Creates autostart registry keys to launch java 50->151 153 Injects code into the Windows Explorer (explorer.exe) 50->153 155 Exploit detected, runtime environment starts unknown processes 50->155 169 2 other signatures 50->169 63 explorer.exe 50->63         started        67 conhost.exe 50->67         started        69 chrome.exe 54->69         started        157 Writes to foreign memory regions 56->157 159 Allocates memory in foreign processes 56->159 161 Modifies the context of a thread in another process (thread injection) 56->161 71 conhost.exe 56->71         started        73 explorer.exe 56->73         started        115 monitor.telemetry-controlsystem.in.net 60->115 117 172.67.201.206, 443, 49724, 49725 CLOUDFLARENET-CloudflareIncUS Canada 60->117 119 dist.vertexengine.cc 60->119 163 System process connects to network (likely due to code injection or exploit) 60->163 165 Tries to steal Crypto Currency Wallets 60->165 167 Found direct / indirect Syscall (likely to bypass EDR) 60->167 75 chrome.exe 60->75         started        file13 signatures14 process15 dnsIp16 121 lb.propertyfind.cc 104.21.15.70, 443, 49743 CLOUDFLARENET-CloudflareIncUS Canada 63->121 123 aaf0e58824b44ab71.awsglobalaccelerator.com 76.223.55.101, 443, 49742 AMAZON-02-AmazoncomIncUS United States 63->123 127 System process connects to network (likely due to code injection or exploit) 63->127 129 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 63->129 131 Unusual module load detection (module proxying) 63->131 125 www.google.com 142.251.152.119, 443, 49731, 49733 GOOGLE-GoogleLLCUS United States 69->125 signatures17
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Lazy
Status:
Malicious
First seen:
2026-07-30 03:14:34 UTC
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
sectoprat
Score:
  10/10
Tags:
family:animateclipper family:sectoprat bootkit clipper defense_evasion discovery persistence rat spyware stealer trojan
Behaviour
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Location Discovery: System Language Discovery
System Time Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks whether UAC is enabled
Writes to the Master Boot Record (MBR)
Checks BIOS information in registry
Executes dropped EXE
Loads dropped DLL
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Detects AnimateClipper
Family: AnimateClipper,ZigClipper
Family: SectopRAT
SectopRAT payload
Suspicious use of NtCreateUserProcessOtherParentProcess
Malware Config
C2 Extraction:
bsc.rpc.blxrbdn.com
Unpacked files
SH256 hash:
42d00bbf109d84bf076159af48932d3354d76daecf049fd09559dba48d3b5d21
MD5 hash:
e8a57773a2cbc39610a3707a175e02ac
SHA1 hash:
228f0bddad60a54084c91a8703d346bafb95e16d
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:MAL_Trigon_Dropper
Author:jaszzz
Description:Trigon multi-stage malicious dropper - process injection, keylogging, screenshot capture
Reference:URL|trigon
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments