🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f6382d6291afbcaddb90da37f6c1f6ad55cc4e9b3e17de6c75e62eff9598edd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TRYMELocker


Vendor detections: 13


Intelligence 13 IOCs YARA 11 File information Comments

SHA256 hash: 5f6382d6291afbcaddb90da37f6c1f6ad55cc4e9b3e17de6c75e62eff9598edd
SHA3-384 hash: d2de881d9d087d85d2e0734b5fb07aba0ea6061e0a3ec15f521e569807df2e66cd611de647b8984fbd01ead8d02c83ef
SHA1 hash: 9eb66d1231c6c7e102ce91d207ada982e3e3f0a5
MD5 hash: efa0aeb1ee3dac26deb0ee1c4e233a99
humanhash: jig-paris-july-uniform
File name:5f6382d6291afbcaddb90da37f6c1f6ad55cc4e9b3e17de6c75e62eff9598edd
Download: download sample
Signature TRYMELocker
File size:26'624 bytes
First seen:2026-05-26 11:32:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 384:KUlOyj1hF/q05ul9+K0b6SFDMH4YlTYbGGqTrJHehHQZJHljgCrPBXTl1nHBwLdp:Ka/q0Uvv05LYCbyg6llTlAd
TLSH T17BC2D604B7FC4A24F2BE4F35197961404B3BBE169C22D75E0AC45D8E18767C88BA2B27
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter Threatray
Tags:exe TRYMELocker

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
RMP (1).exe
Verdict:
Malicious activity
Analysis date:
2026-05-10 16:21:29 UTC
Tags:
telegram

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
ransomware virus blic
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file in the Windows subdirectories
Adding an access-denied ACE
Searching for the window
Creating a window
Creating a file
Creating a process from a recently created file
Creating a process with a hidden window
Forced system process termination
Sending a custom TCP request
Setting a keyboard event handler
Enabling the libraries to load when starting the app (AppInit_DLLs)
Creating a service
Loading a suspicious library
Forced shutdown of a system process
Unauthorized injection to a recently created process
Enabling autorun for a service
Enabling autorun
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-security base64 cmd explorer fingerprint krypt lolbin reconnaissance regedit schtasks telegram
Verdict:
Malicious
Labled as:
Capa_reference_analysis_tools_strings
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-10T14:51:00Z UTC
Last seen:
2026-05-28T04:43:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.MSIL.Dnoper.gen Trojan.Win32.Diztakun.sb Trojan.Multi.Agent.sb Trojan.MSIL.Dnoper.sb PDM:Trojan.Win32.Tasker.cust PDM:Trojan.Win32.Generic
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-05-12 08:40:54 UTC
File Type:
PE (.Net Exe)
Extracted files:
3
AV detection:
25 of 37 (67.57%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
trymelocker
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution exploit persistence
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Launches sc.exe
File and Directory Permissions Modification: Windows File and Directory Permissions Modification
Checks computer location settings
Creates new service(s)
Executes dropped EXE
Modifies file permissions
Possible privilege escalation attempt
Unpacked files
SH256 hash:
5f6382d6291afbcaddb90da37f6c1f6ad55cc4e9b3e17de6c75e62eff9598edd
MD5 hash:
efa0aeb1ee3dac26deb0ee1c4e233a99
SHA1 hash:
9eb66d1231c6c7e102ce91d207ada982e3e3f0a5
SH256 hash:
62661ee9a42950ffdc5494169598b5fb859de11f47aade0e82325d1ef6bec1e6
MD5 hash:
81b22aa3f3ce62d2aa67415e3b556caa
SHA1 hash:
3eaf4b19725d8c0dfea4c85972377fbf7b6f6777
SH256 hash:
b6353c3fa3cb584a7092833eaedab4478fda10ed385a2bb1749566e7653e74df
MD5 hash:
4bc5776e3c5f8410338cfc691141361e
SHA1 hash:
623e0fbc96a7d355968cb03ca71a1b64dccc6d09
SH256 hash:
ef69be19daefb27258d611d1847f15aedee878eed28a4138150b124382ee1a2d
MD5 hash:
843f7498e7aaea4349c6578ac9540889
SHA1 hash:
6c9c3ac819285e9a32aa385cb4e7e4b37d98b343
SH256 hash:
b46e26f56bcca8627ec2af829876644592317b8f4fbd70fd81359c4833cff203
MD5 hash:
69d408286919006ac1b651635be6b167
SHA1 hash:
724183d26dbb10573661d83f570fa9d4dc99c95f
SH256 hash:
10c65bce9eaf110cad6763f23bfee8a655d4fad4ed448230c336834c3c48b3a5
MD5 hash:
caa1e184e08ac2045b4369128b5a7915
SHA1 hash:
9c6b899759965a6a2927a953f3ebc1a6d1a68fc2
SH256 hash:
7b413c5fe885becfc429021b22abb9235c4a2ce02c17084d48b90883eccf5e8b
MD5 hash:
24df44ec0fe656f63579b5b8111c4a57
SHA1 hash:
fe05ebc74e9ad3c43dae6308e1db693a842de5b4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Author:ditekSHen
Description:Detects executables using Telegram Chat Bot
Rule name:INDICATOR_SUSPICIOUS_GENRansomware
Author:ditekSHen
Description:Detects command variations typically used by ransomware
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_VBS_Wscript_Shell
Author:SECUINFRA Falcon Team
Description:Detects the definition of 'Wscript.Shell' which is often used by Malware, FPs are possible and commmon
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TelegramAPIMalware_PowerShell_EXE
Author:@polygonben
Description:Hunting for pwsh malware using Telegram for C2
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments