MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5f1454b656526752df4f393b86fd3fa41446cb486d7781fc96957c2849d69e8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
VIPKeylogger
Vendor detections: 17
| SHA256 hash: | 5f1454b656526752df4f393b86fd3fa41446cb486d7781fc96957c2849d69e8b |
|---|---|
| SHA3-384 hash: | 3a25259e71e6536acf418ac5ca17d0ff02c3e73a29b60f28737a36f475eccd09ba8eb8c9d1c8a657226448b2651dab86 |
| SHA1 hash: | 001ca1cd8d6122a2f9205d44b194bb73d01f4b80 |
| MD5 hash: | b2a4215d756fbf60d605a284bb5d6b86 |
| humanhash: | neptune-king-queen-texas |
| File name: | 5f1454b656526752df4f393b86fd3fa41446cb486d7781fc96957c2849d69e8b |
| Download: | download sample |
| Signature | VIPKeylogger |
| File size: | 1'101'824 bytes |
| First seen: | 2026-02-05 15:20:34 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'795 x AgentTesla, 19'692 x Formbook, 12'274 x SnakeKeylogger) |
| ssdeep | 24576:Cu2mI58EWn7LRog48yIwS66XkWgwHTR/lMSq3QWL1CwI:CHmIKVl7Bwtgf9zR/lMSZWL |
| Threatray | 1 similar samples on MalwareBazaar |
| TLSH | T10C351295BB4ECA03DDA5877509B0E33203B8AE69E921D3074EEC7CEB3874F445985792 |
| TrID | 35.4% (.EXE) Win64 Executable (generic) (10522/11/4) 22.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.1% (.EXE) Win32 Executable (generic) (4504/4/1) 6.9% (.ICL) Windows Icons Library (generic) (2059/9) 6.8% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| Reporter | |
| Tags: | exe VIPKeylogger |
Intelligence
File Origin
HUVendor Threat Intelligence
Details
Result
Behaviour
Unpacked files
be2142e2818d4df10efca8b223a823dae8dbcc0679e8e19a94fa9ae729c34273
1e0bbcaa4d9b3f4c144e10dad6fb9ecbde607e3c48c2d3194195f56852ef8ffb
3e4a68bdf48f606bad0af48e31d1776d5f5b82574d39cc320445f862d463a063
0249b099e5cf161407b30450caa1c6c778180293c336ac5990a7711cb4019ce5
ba1473e8daf2c65a904ab244102c92a49938f34af94502b920ca2d324c1f3017
ceaa3016ce3897c17e580b58f2a41cc247de57bada3271b30aa389bcf3787ea0
d1c9c2f4cfd087b3eb5d7ece5b4a9111c494bc34217b4d60ab85beba1a36e082
5f1454b656526752df4f393b86fd3fa41446cb486d7781fc96957c2849d69e8b
50681a74fd565805b9fa7d22dcb00ff4578b6821cdefb8c4d0f0da619f5621ca
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.