🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bde3658d00b47ba87779f449ae65235d48fa6c36f79b1b5e00d095c4c649e21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 5bde3658d00b47ba87779f449ae65235d48fa6c36f79b1b5e00d095c4c649e21
SHA3-384 hash: ece5488d62700efd2df7c4955078ccf22fa32f9eefd992acc0c5876196f48f65596771ec1d966cd49000d704043125f2
SHA1 hash: 60c9987af698ea5e66c0663545099c1e2720588e
MD5 hash: 0b21cf19ac5249d378a64302008849ac
humanhash: sodium-december-connecticut-dakota
File name:file
Download: download sample
File size:11'153'920 bytes
First seen:2026-09-25 16:01:23 UTC
Last seen:2026-09-26 11:19:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 884759b875c229ccd717c8f5cd909ef7
ssdeep 98304:1W9iAG7MdkU9UiH2l+Eaq4R8HVey7LYnu1bXwW7xOdxSBLxNuaMCdQwn:k67Mdh3s+E4Wo2Mu1bXinWNuaM6QG
TLSH T150B63D21D50803E5F829E3BE4AC93FB96E143F2AA1356418A7DE1593B112EB1E7F53C4
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon f1e886966e168ce0
Reporter Bitsight
Tags:dropped-by-Stealc exe payload_proxy_v1


Avatar
Bitsight
url: https://fortworthpca.org/.tmb/localjournal5.exe

Intelligence


File Origin
# of uploads :
14
# of downloads :
207
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-25 16:05:15 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Launching a service
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug fingerprint microsoft_visual_cc packed
Verdict:
Unknown
File Type:
exe x64
First seen:
2026-09-25T12:36:00Z UTC
Last seen:
2026-09-27T02:59:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.AdvML
Status:
Malicious
First seen:
2026-09-25 16:02:40 UTC
File Type:
PE+ (Exe)
Extracted files:
5
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
5bde3658d00b47ba87779f449ae65235d48fa6c36f79b1b5e00d095c4c649e21
MD5 hash:
0b21cf19ac5249d378a64302008849ac
SHA1 hash:
60c9987af698ea5e66c0663545099c1e2720588e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 5bde3658d00b47ba87779f449ae65235d48fa6c36f79b1b5e00d095c4c649e21

(this sample)

  
Dropped by
StealC
  
Delivery method
Distributed via web download

Comments