🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47671e892be8809f5c7c1f127733afcd5ee27d2c78db20e48f7794175c76cd97. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 47671e892be8809f5c7c1f127733afcd5ee27d2c78db20e48f7794175c76cd97
SHA3-384 hash: 1a830edaefbff5344d44cb84312b019c20da8269f432862164ca870a4ecb55e14a8f0834306eed131fae6dea91ad8c56
SHA1 hash: 93eb0d0cb44582f85df7b02733ad58322f281f08
MD5 hash: 790a8f563962f22e367768edbf4bfe19
humanhash: johnny-asparagus-mike-asparagus
File name:ProtobufLite.dll
Download: download sample
File size:150'887'296 bytes
First seen:2026-09-23 02:26:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ad9fe34fe5f9267ff1c10d689801a190
ssdeep 393216:Pq43p9CrNhfwyGeISASXc7kVpnZTNz1IJ0grPlCJqhxhkjS76ydzkUB0WDxOVDh:ghf1LI4X7pnpNmJRJCJ6ajad4WDx6Dh
TLSH T17A78AFB273C4EEFAC041D97A5705F23181A2986E8BB691C46F92870A5DF5A114F3CBDC
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Parper
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'125
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-09-22T23:29:00Z UTC
Last seen:
2026-09-23T00:05:00Z UTC
Hits:
~10
Detections:
Trojan.Win64.Reflo.sb Trojan.Win64.Agent.sb Trojan.Win32.Inject.sb HEUR:Trojan.Win64.Aotnet.gen
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-23 02:27:37 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments