MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 464f3d79673b3bd8bc3b9f3ddafe38275256b2edc870f5a80bcfa1574d18edcb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 10 File information Comments

SHA256 hash: 464f3d79673b3bd8bc3b9f3ddafe38275256b2edc870f5a80bcfa1574d18edcb
SHA3-384 hash: ff7e61752c44bb249afec06a06a0229e411de236ec5d67251c824c9165bb5fd756f4e6d2d395236491fa268508f7be0d
SHA1 hash: 7871879b6e7e649b7df001ddcd9f61b27f730c76
MD5 hash: 049ec27ea3b154f03f8baba26dae3308
humanhash: west-california-sad-failed
File name:464f3d79673b3bd8bc3b9f3ddafe38275256b2edc870f5a80bcfa1574d18edcb
Download: download sample
File size:1'314'816 bytes
First seen:2026-08-10 14:31:36 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4ca36c0623611345ee5fabf3cf68d4e0 (1 x Phorpiex)
ssdeep 24576:EqqyOTWxNBxj3oElG4ADM8pa495kQwFn3nWBWic9uRt2Nr:EqqyOWBxVlG4cPs49fmtic9lr
TLSH T12355BF21B69790F3D6553A7014BA2B3F9E3DAA460B24DBC39364EE2C6C331C19D3715A
TrID 23.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.8% (.EXE) UPX compressed Win32 Executable (27066/9/6)
20.4% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
12.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
Magika pebin
dhash icon d0d9a9e0d2d1c940 (1 x Phorpiex)
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug iceid keylogger microsoft_visual_cc packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-10T12:51:00Z UTC
Last seen:
2026-08-11T02:48:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2026-08-10 14:53:29 UTC
File Type:
PE (Exe)
Extracted files:
157
AV detection:
19 of 36 (52.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery persistence upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
System Location Discovery: System Language Discovery
UPX packed file
Adds Run key to start application
Executes dropped EXE
Unpacked files
SH256 hash:
464f3d79673b3bd8bc3b9f3ddafe38275256b2edc870f5a80bcfa1574d18edcb
MD5 hash:
049ec27ea3b154f03f8baba26dae3308
SHA1 hash:
7871879b6e7e649b7df001ddcd9f61b27f730c76
Detections:
triage_uuloader_loader
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Hacktools_CN_Panda_andrew
Author:Florian Roth
Description:Disclosed hacktool set - file andrew.exe - sethc.exe Debugger backdoor
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments