🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b86039fe4d2dd87a71ad17b026cbb5dcba8e3d63fe026adb7a995fc60826189. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 6 File information Comments

SHA256 hash: 5b86039fe4d2dd87a71ad17b026cbb5dcba8e3d63fe026adb7a995fc60826189
SHA3-384 hash: bba94fb63ea7a2b11a677c543b14c37e1239a85a633537f986a9fcfe196e54e5e1d05b5f89953f194224d62aa3593ffe
SHA1 hash: dfb539a7575502e8259aed86a4e23dd760365b9d
MD5 hash: fa05844a7e78e3ce97cea58b4eef778b
humanhash: crazy-november-alanine-louisiana
File name:5b86039fe4d2dd87a71ad17b026cbb5dcba8e3d63fe026adb7a995fc60826189.exe
Download: download sample
File size:2'999'946 bytes
First seen:2026-09-24 10:08:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (26 x ValleyRAT, 20 x OffLoader, 14 x Tofsee)
ssdeep 49152:BuI2hhNF6qa2x0npAJF7ICq+ZIAipU+dPnHdGA/38+9f3Wppuz:B5OhNFEC0npsF7I4ZI/ZHdx38GfGp4
TLSH T1C5D5F13FB28B613EE06E5A367A76E210583B7A6165178C16D7E4C88CCF250701E3E797
TrID 61.4% (.EXE) Inno Setup installer (107240/4/30)
23.8% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.7% (.EXE) Win64 Executable (generic) (6522/11/2)
2.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon cc31e0e8f071b2cc
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Suspicious activity
Analysis date:
2026-09-24 10:45:27 UTC
Tags:
delphi inno installer auto-reg

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Launching a service
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-09-24T08:06:00Z UTC
Last seen:
2026-09-24T08:35:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
40 / 100
Signature
Bypasses PowerShell execution policy
Creates autostart registry keys with suspicious names
Inline Python code execution detected
Loading BitLocker PowerShell Module
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Suspicious execution chain found
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1977534 Sample: YlLh43ttDJ.exe Startdate: 24/09/2026 Architecture: WINDOWS Score: 40 101 www.python.org 2->101 103 ideas-irisselection-irisfd-lb.prod-b-wus2.ideas-irisselection-irisfd.westus2-prod.cosmic.office.net 2->103 105 7 other IPs or domains 2->105 111 Multi AV Scanner detection for submitted file 2->111 113 Yara detected Powershell download and execute 2->113 10 msiexec.exe 2->10         started        13 YlLh43ttDJ.exe 2 2->13         started        15 python-3.12.10-amd64.exe 2->15         started        17 python-3.12.10-amd64.exe 2->17         started        signatures3 process4 file5 91 C:\Users\user\AppData\...\expatreader.py, Python 10->91 dropped 93 C:\Users\user\AppData\Local\...\pythonw.exe, PE32+ 10->93 dropped 95 C:\Users\user\AppData\Local\...\python.exe, PE32+ 10->95 dropped 99 205 other files (none is malicious) 10->99 dropped 19 msiexec.exe 10->19         started        97 C:\Users\user\AppData\...\YlLh43ttDJ.tmp, PE32 13->97 dropped 21 YlLh43ttDJ.tmp 25 28 13->21         started        25 python-3.12.10-amd64.exe 15->25         started        27 python-3.12.10-amd64.exe 17->27         started        process6 file7 29 python.exe 19->29         started        65 C:\Users\user\AppData\...\is-IAE8F13H13.tmp, ASCII 21->65 dropped 67 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 21->67 dropped 69 C:\Users\user\AppData\...\unins000.exe (copy), PE32 21->69 dropped 71 15 other files (none is malicious) 21->71 dropped 115 Bypasses PowerShell execution policy 21->115 32 powershell.exe 28 21->32         started        34 python-3.12.10-amd64.exe 25->34         started        37 python-3.12.10-amd64.exe 27->37         started        signatures8 process9 file10 119 Inline Python code execution detected 29->119 39 python.exe 29->39         started        42 conhost.exe 29->42         started        121 Suspicious execution chain found 32->121 123 Maps a DLL or memory area into another process 32->123 125 Loading BitLocker PowerShell Module 32->125 44 python-3.12-setup.exe 3 32->44         started        46 curl.exe 2 32->46         started        49 AppInstallerPythonRedirector.exe 32->49         started        51 conhost.exe 32->51         started        59 C:\Users\user\AppData\Local\...\PythonBA.dll, PE32 34->59 dropped 61 C:\Users\user\AppData\...\DEL14A9.tmp (copy), PE32 34->61 dropped 63 C:\Users\user\AppData\Local\...\PythonBA.dll, PE32 37->63 dropped signatures11 process12 dnsIp13 73 C:\Users\user\AppData\Local\...\pip3.exe, PE32+ 39->73 dropped 75 C:\Users\user\AppData\Local\...\pip3.12.exe, PE32+ 39->75 dropped 77 C:\Users\user\AppData\Local\...\pip.exe, PE32+ 39->77 dropped 83 390 other files (none is malicious) 39->83 dropped 53 cmd.exe 39->53         started        79 C:\Windows\Temp\...\python-3.12-setup.exe, PE32 44->79 dropped 55 python-3.12-setup.exe 54 51 44->55         started        107 dualstack.python.map.fastly.net 151.101.64.223, 443, 49713 FASTLY-FastlyIncUS Canada 46->107 109 127.0.0.1 unknown unknown 46->109 81 C:\Users\user\...\python-3.12-setup.exe, PE32 46->81 dropped file14 process15 file16 85 C:\Windows\Temp\...\python-3.12.10-amd64.exe, PE32 55->85 dropped 87 C:\Windows\Temp\...\PythonBA.dll, PE32 55->87 dropped 89 C:\Users\user\...\python-3.12.10-amd64.exe, PE32 55->89 dropped 117 Creates autostart registry keys with suspicious names 55->117 signatures17
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution installer persistence
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
cURL User-Agent
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Badlisted process makes network request
Checks installed software on the system
Command and Scripting Interpreter: PowerShell
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
Unpacked files
SH256 hash:
5b86039fe4d2dd87a71ad17b026cbb5dcba8e3d63fe026adb7a995fc60826189
MD5 hash:
fa05844a7e78e3ce97cea58b4eef778b
SHA1 hash:
dfb539a7575502e8259aed86a4e23dd760365b9d
SH256 hash:
62453c629af35b2f84fdd017c9d350893400fdd0f06d770eb45ea14c630451fb
MD5 hash:
ee4aa05ffad2a26a48cf760d9cdc3473
SHA1 hash:
e6df0ee2057bbb51566c8d9a2466d6cff2b35bba
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 5b86039fe4d2dd87a71ad17b026cbb5dcba8e3d63fe026adb7a995fc60826189

(this sample)

  
Delivery method
Distributed via web download

Comments