MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54d788b1af6ba0343256e528aadfaae30e2ad214e7a6915dc08f0dddc23b2f2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 13


Intelligence 13 IOCs YARA 1 File information Comments

SHA256 hash: 54d788b1af6ba0343256e528aadfaae30e2ad214e7a6915dc08f0dddc23b2f2c
SHA3-384 hash: 6be691d4a4c36dcce3196f81729851be725513e935cfd1f8cb96bf977e2ff6bec04bf11421ac80722a5f955648df18bc
SHA1 hash: 7f6ae8f83b6d4cf9d1494221c14437942b9e9152
MD5 hash: ca4069130468d93ac7c719bf89f792c8
humanhash: vegan-muppet-kansas-ink
File name:Game.exe
Download: download sample
File size:4'386'187 bytes
First seen:2026-04-02 19:46:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9dda1a1d1f8a1d13ae0297b47046b26e (65 x Formbook, 48 x GuLoader, 28 x RemcosRAT)
ssdeep 98304:qGRoaRfCxu9X/K4JIPXZMUiaBEp0eDYmqFxYrP3bwKaDZnq5hTah:qhaR9PKB/di8w0ipmYrfKDsy
TLSH T1B4163336F13A7838D0E31ABE6D5219203CA7BDA68644DB0F2F1530A657F1397B5097AC
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 79fcf878f978b0c8
Reporter KnownSpotter
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
CA CA
Vendor Threat Intelligence
Gathering data
Malware family:
n/a
ID:
1
File name:
Game.exe
Verdict:
Malicious activity
Analysis date:
2025-12-14 15:39:47 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
shell sage smtp
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Сreating synchronization primitives
Creating a process from a recently created file
Modifying an executable file
Unauthorized injection to a recently created process
Restart of the analyzed sample
Searching for synchronization primitives
Creating a file
Sending a custom TCP request
Launching the default Windows debugger (dwwin.exe)
Running batch commands
Creating a process with a hidden window
Launching a process
Moving a recently created file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 cmd findstr installer installer installer-heuristic lolbin microsoft_visual_cc nsis powershell reg soft-404
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-12-06T11:02:00Z UTC
Last seen:
2026-04-04T13:17:00Z UTC
Hits:
~10000
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
84 / 100
Signature
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Uses cmd line tools excessively to alter registry or file data
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
n/a
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Verdict:
Malicious
Threat:
Trojan-Clicker.Script.GhostPlugin
Threat name:
Win32.Trojan.Ghostplugin
Status:
Malicious
First seen:
2025-12-06 15:53:51 UTC
File Type:
PE (Exe)
Extracted files:
42
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution upx
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Views/modifies file attributes
Browser Information Discovery
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Hide Artifacts: Ignore Process Interrupts
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
https://xiansearch.com/xext?i=
Unpacked files
SH256 hash:
54d788b1af6ba0343256e528aadfaae30e2ad214e7a6915dc08f0dddc23b2f2c
MD5 hash:
ca4069130468d93ac7c719bf89f792c8
SHA1 hash:
7f6ae8f83b6d4cf9d1494221c14437942b9e9152
SH256 hash:
c456ffed86f927a9f616577d26384f2fd048d62c54e8890819a90c1645661a2d
MD5 hash:
7c39de3014973865083166184d482051
SHA1 hash:
3c839d69fc3d3086226056c0a9df85db73a3072b
SH256 hash:
5b7da7053c496c6285b3429128bef5bed0337f9fabe577cdd5f95ecd3a30f644
MD5 hash:
50d8a6229348bcba5082635a3ff9236b
SHA1 hash:
30d68296ab18130a8c50c7829e7d0a898c736930
SH256 hash:
0e7efca312cb6618205833f6fd24e4db9a1315c5d4d17ae55f21c1d8f26c1096
MD5 hash:
96607a997a31f5e9ba333708f601b33b
SHA1 hash:
54453d250359e55c8ddb075d99b46b55273e51f4
SH256 hash:
f7487be70a63f129f02b0ac42c0f21bdb85f247e305498e6bd34f3696504ee04
MD5 hash:
05abe471c15189b07d190fbd2d50545a
SHA1 hash:
ba70aee2688a88539476a5d49fce3ffdbb893c22
SH256 hash:
9111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706
MD5 hash:
4add245d4ba34b04f213409bfe504c07
SHA1 hash:
ef756d6581d70e87d58cc4982e3f4d18e0ea5b09
SH256 hash:
ddf4a6f754c3f699c48b429c984f0da3fc89df485b73108e37fe388eb9275d6d
MD5 hash:
54fd052e0475b3cbe39cdf6a31836b84
SHA1 hash:
cb1beef2187e878e23d0429fb309be32154b29de
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments