🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d0b36692f572c628f2e14eb0caabf6790aa486ec28d7573a28c9d0463ec6215. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DCAgentRMM


Vendor detections: 3


Intelligence 3 IOCs YARA 3 File information Comments

SHA256 hash: 4d0b36692f572c628f2e14eb0caabf6790aa486ec28d7573a28c9d0463ec6215
SHA3-384 hash: e9b6742a00b771b3bff65e115af42e343e3a3b829a250c1d90feb06b37ad53a8f53132c08d7acbc7b3acca4107490bc8
SHA1 hash: f661f37cee39db948e8ea3e0289f36648f89554e
MD5 hash: 18659868a92652a7a9b1b8781b21baba
humanhash: dakota-cardinal-golf-freddie
File name:file.zip
Download: download sample
Signature DCAgentRMM
File size:62'387'278 bytes
First seen:2026-09-15 06:39:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:wf+13RICQsGJIx1mM2PARXTbMZZrmel8gE3kqhrlxY5GxBN5XG579SmmL:wmrIG0Ix1JVRbMrrmzgEU2lxc+ZG9SmO
TLSH T14FD733EB9458CB9AC89ED01049D83F4C5D1A06E1D0A8813FFB657BDDA0D8FC2716D2B9
Magika zip
Reporter skocherhan
Tags:156-245-245-223 DCAgentRMM dnswwt-club ManageEngine zip


Avatar
skocherhan
http://dnswwt.club/down/file.zip

C2
156.245.245.223:8383

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
GB GB
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:DMRootCA-Server.crt
File size:1'410 bytes
SHA256 hash: 4961d9f87d992116902719726e0e1dcbaef67395dd0ff4cbc8f6a61981269c1d
MD5 hash: 91b56071382de99ed235f7655f73b1a0
MIME type:text/plain
Signature DCAgentRMM
File name:README.html
File size:1'332 bytes
SHA256 hash: 02595856ad354a47e9c664a55dc428aad19ce73a00fe95228bbe590cfca944d8
MD5 hash: 2d939d7afe37b02f77e4eb4d5e5916fc
MIME type:text/html
Signature DCAgentRMM
File name:UEMSAgent.mst
File size:20'480 bytes
SHA256 hash: 8dd93f43089a682cbac39c0a1f364057dcb7d08e9b1480c088f15a5dd56d8be4
MD5 hash: 0273976d2ecf588a5514b0f5069968e5
MIME type:application/vnd.ms-msi
Signature DCAgentRMM
File name:DCAgentServerInfo.json
File size:4'633 bytes
SHA256 hash: ec7cac9eab79c5236ffb0be7e5a9a9925ae1a3c9856f09d93fc13bc8dc829aec
MD5 hash: b85fcc747ffb1d89132a3141aab6376e
MIME type:application/json
Signature DCAgentRMM
File name:setup.bat
File size:3'047 bytes
SHA256 hash: 91f784bf3dd83c0f5135ac1fd00a0fdd430720ebc57ec4c2eccb7875dbc8a90d
MD5 hash: 9cb71612a1aa60c6a9c893bcefced81f
MIME type:text/x-msdos-batch
Signature DCAgentRMM
File name:DMRootCA.crt
File size:1'442 bytes
SHA256 hash: c32c8d84f7120e3a66e6ef38ab119e0a9a7c45d1170e52f71f71d7736b01bbdd
MD5 hash: d829c0a2f36bae190d6a1b6e6a1acb18
MIME type:text/plain
Signature DCAgentRMM
File name:UEMSAgent.msi
File size:63'240'704 bytes
SHA256 hash: 9392dabf5b4a1d41329143c232e5130ad56e4ce1b5973372623e7982f683bbe2
MD5 hash: 71e42f702ef3eb9906143f754ef85697
MIME type:application/x-msi
Signature DCAgentRMM
Vendor Threat Intelligence
Gathering data
Verdict:
Unknown
File Type:
zip
First seen:
2026-09-14T04:45:00Z UTC
Last seen:
2026-09-16T23:10:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:NET
Author:malware-lu

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DCAgentRMM

zip 4d0b36692f572c628f2e14eb0caabf6790aa486ec28d7573a28c9d0463ec6215

(this sample)

  
Delivery method
Distributed via web download

Comments