MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566
SHA3-384 hash: b773c908bf0dd5de06cc997e61e2ded9c637269b642dc2c0b8f79262982f2d82c00a1a46558a720c54f0db5f803312dd
SHA1 hash: 821c0cafb2aab0f063ef7e313f64313fc81d46cd
MD5 hash: a8860bb5ccb964273b7fd2284b9dc837
humanhash: paris-edward-nebraska-arkansas
File name:1243.exe
Download: download sample
File size:153'023 bytes
First seen:2026-08-08 14:32:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5e48fbae3520a62c95e412b293e1759c (2 x ValleyRAT, 1 x PureLogsStealer)
ssdeep 3072:QTNcYz/WYtKauuPNXbChjNrKCdTLdp97HcsgWBORZKiCo4aA0:QTNcYS2JCKOdp0WBcZ5Cvn0
TLSH T148E302277FE0C673FC9A0B701E365F6396BBD5142421CB0B83909A45FA21785DE662F2
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter BlinkzSec
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
AutoUpdater.exe.7z
Verdict:
Malicious activity
Analysis date:
2025-10-27 11:16:34 UTC
Tags:
arch-exec stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Searching for the window
Searching for the Windows task manager window
Running batch commands
Creating a process with a hidden window
Launching a process
Creating a file in the %AppData% subdirectories
Launching a service
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Deleting a recently created file
Query of malicious DNS domain
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-10-17T08:17:00Z UTC
Last seen:
2026-08-09T11:34:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.FatBeehive
Status:
Malicious
First seen:
2025-10-18 17:48:00 UTC
File Type:
PE (Exe)
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution
Behaviour
Gathers network information
Gathers system information
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Network Connections Discovery
Discovers running processes
Executes dropped EXE
Loads dropped DLL
Unpacked files
SH256 hash:
4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db4566
MD5 hash:
a8860bb5ccb964273b7fd2284b9dc837
SHA1 hash:
821c0cafb2aab0f063ef7e313f64313fc81d46cd
SH256 hash:
b761cfff492e1978faba5b92d23e1e718c78f7d3de610c850b3fd2d13511f173
MD5 hash:
89c889f120f46b5199a428011528a861
SHA1 hash:
200c10a16f250540fc568a7fcea1060a193d1b40
SH256 hash:
e5f5583fc1e5229f4f44bb72d8de22f270f91577b48cd6d025ad78ee4edea357
MD5 hash:
85bd58a837b4168c133548de303e8a2c
SHA1 hash:
2693a9725bb2070e14d720e4a8f7ebf6f768b1f8
SH256 hash:
c35bd9c41022d56df42b943c9f183a3c6e3ff23a880d14d796b6d86d0a64076a
MD5 hash:
a98a5062703f660195da7e419db5b686
SHA1 hash:
bf996a709835c0c16cce1015e6d44fc95e08a38a
SH256 hash:
3f3c0c8feb7eb2019827904cc7614be3954abc856eefab67cd31b3bd72c3599a
MD5 hash:
8b1dee1e7178f9c4e92e9f073307b8ad
SHA1 hash:
2ab0758dda4e71aee6f4c8e4c0265a796518f07d
SH256 hash:
9aa3ca96a84eb5606694adb58776c9e926020ef184828b6f7e6f9b50498f7071
MD5 hash:
24b6950afd8663a46246044e6b09add8
SHA1 hash:
6444dab57d93ce987c22da66b3706d5d7fc226da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments