MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fe3446e6ed09ff8b8dc0890888af2ca7bb4fa1acc5281acf64b5ef5d6420774. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BlankGrabber


Vendor detections: 19


Intelligence 19 IOCs YARA 31 File information Comments

SHA256 hash: 5fe3446e6ed09ff8b8dc0890888af2ca7bb4fa1acc5281acf64b5ef5d6420774
SHA3-384 hash: ee81006004bf9b5d0d809e3a23b3b6c9c7bff84df80cb71141a4e745c5ee64e42ad993ed8ba15577666500324664c37a
SHA1 hash: 2641f306f1a766f26595b837754a5f04a7852e1c
MD5 hash: 5e3da9cb266b107730f517d0f7db4954
humanhash: freddie-single-nineteen-washington
File name:1111.exe
Download: download sample
Signature BlankGrabber
File size:6'652'576 bytes
First seen:2025-04-29 20:09:08 UTC
Last seen:2025-06-03 18:06:04 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 12e12319f1029ec4f8fcbed7e82df162 (486 x NirCmd, 393 x DCRat, 52 x RedLineStealer)
ssdeep 196608:TmPbXblfzTugTiVCAfmRc7oYXneo4Z0Hkfw/in:4fzTugTKfocxeo4SkfwKn
Threatray 2'267 similar samples on MalwareBazaar
TLSH T11366121665E25E3BC2A05B715497013D92E5DB323E61EF4B365F10E6AA037F0CB321AB
TrID 89.0% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
3.5% (.EXE) Win64 Executable (generic) (10522/11/4)
2.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
1.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
1.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 9494b494d4aeaeac (904 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter skocherhan
Tags:BlankGrabber exe github-penivai3sdfs1


Avatar
skocherhan
https://github.com/penivai3sdfs1/1/raw/refs/heads/main/1111.exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
587
Origin country :
GB GB
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
https://raw.githubusercontent.com/penivai3sdfs1/1/refs/heads/main/24321.exe
Verdict:
Malicious activity
Analysis date:
2025-04-28 20:52:38 UTC
Tags:
github evasion stealer dcrat rat remote darkcrystal umbralstealer discord exfiltration zerotrace xor-url generic arch-doc winring0x64-sys vuln-driver xworm gotfucked

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect asyncrat phishing
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Creating a process from a recently created file
Running batch commands
Creating a process with a hidden window
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending an HTTP GET request
Loading a suspicious library
Creating a file in the Program Files subdirectories
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm anti-vm asyncrat backdoor cmd config-extracted crypt dcrat explorer fingerprint fingerprint hacktool installer lolbin lolbin microsoft_visual_cc njrat obfuscated overlay overlay packed packed packer_detected rat reconnaissance schtasks sfx wmic xworm
Malware family:
Sharp Stealer
Verdict:
Malicious
Result
Threat name:
Blank Grabber, DCRat, PureLog Stealer, U
Detection:
malicious
Classification:
troj.adwa.spyw.expl.evad.mine
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Changes security center settings (notifications, updates, antivirus, firewall)
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Drops executable to a common third party application directory
Drops executables to the windows directory (C:\Windows) and starts them
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies power options to not sleep / hibernate
Modifies the context of a thread in another process (thread injection)
Modifies the hosts file
Modifies Windows Defender protection settings
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Protects its processes via BreakOnTermination flag
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample is not signed and drops a device driver
Sample uses string decryption to hide its real strings
Sigma detected: Disable power options
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Stop EventLog
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses powercfg.exe to modify the power settings
Uses schtasks.exe or at.exe to add and modify task schedules
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Yara detected Blank Grabber
Yara detected DCRat
Yara detected PureLog Stealer
Yara detected Umbral Stealer
Yara detected Xmrig cryptocurrency miner
Yara detected XWorm
Yara detected zgRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1677601 Sample: 1111.exe Startdate: 29/04/2025 Architecture: WINDOWS Score: 100 126 pool.hashvault.pro 2->126 128 ip-api.com 2->128 130 2 other IPs or domains 2->130 152 Suricata IDS alerts for network traffic 2->152 154 Found malware configuration 2->154 156 Malicious sample detected (through community Yara rule) 2->156 158 23 other signatures 2->158 11 1111.exe 4 9 2->11         started        15 tfbrzzhhrzhb.exe 2->15         started        17 svchost.exe 2->17         started        19 4 other processes 2->19 signatures3 process4 file5 108 C:\driverPerf\XClient.exe, PE32 11->108 dropped 110 C:\driverPerf\Umbral.exe, PE32 11->110 dropped 112 C:\driverPerf\SavesRuntimecommon.exe, PE32 11->112 dropped 116 2 other malicious files 11->116 dropped 186 Found many strings related to Crypto-Wallets (likely being stolen) 11->186 21 wscript.exe 1 11->21         started        24 XClient.exe 15 6 11->24         started        28 Umbral.exe 11->28         started        30 123.exe 11->30         started        114 C:\Windows\Temp\qagmbzqbrpsk.sys, PE32+ 15->114 dropped 188 Multi AV Scanner detection for dropped file 15->188 190 Injects code into the Windows Explorer (explorer.exe) 15->190 192 Modifies the context of a thread in another process (thread injection) 15->192 196 3 other signatures 15->196 32 explorer.exe 15->32         started        34 powershell.exe 15->34         started        36 cmd.exe 15->36         started        40 5 other processes 15->40 194 Changes security center settings (notifications, updates, antivirus, firewall) 17->194 38 MpCmdRun.exe 17->38         started        signatures6 process7 dnsIp8 160 Wscript starts Powershell (via cmd or directly) 21->160 162 Windows Scripting host queries suspicious COM object (likely to drop second stage) 21->162 42 cmd.exe 1 21->42         started        136 89.39.121.169, 9000 NG-ASSosBucuresti-Ploiestinr42-44RO Romania 24->136 138 ip-api.com 208.95.112.1, 49716, 49717, 49763 TUT-ASUS United States 24->138 102 C:\Users\user\AppData\Roaming\XClient.exe, PE32 24->102 dropped 164 Multi AV Scanner detection for dropped file 24->164 166 Protects its processes via BreakOnTermination flag 24->166 168 Bypasses PowerShell execution policy 24->168 180 3 other signatures 24->180 51 5 other processes 24->51 140 discord.com 162.159.128.233, 443, 49845 CLOUDFLARENETUS United States 28->140 104 C:\Windows\System32\drivers\etc\hosts, ASCII 28->104 dropped 170 Suspicious powershell command line found 28->170 172 Found many strings related to Crypto-Wallets (likely being stolen) 28->172 182 3 other signatures 28->182 53 8 other processes 28->53 106 C:\ProgramData\...\tfbrzzhhrzhb.exe, PE32+ 30->106 dropped 184 3 other signatures 30->184 44 powershell.exe 30->44         started        55 9 other processes 30->55 142 104.251.123.89, 443, 49725 1GSERVERSUS United States 32->142 174 System process connects to network (likely due to code injection or exploit) 32->174 176 Query firmware table information (likely to detect VMs) 32->176 178 Loading BitLocker PowerShell Module 34->178 47 conhost.exe 34->47         started        57 2 other processes 36->57 49 conhost.exe 38->49         started        59 4 other processes 40->59 file9 signatures10 process11 signatures12 61 SavesRuntimecommon.exe 3 23 42->61         started        65 conhost.exe 42->65         started        198 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 44->198 200 Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines) 44->200 202 Loading BitLocker PowerShell Module 44->202 67 conhost.exe 44->67         started        69 conhost.exe 51->69         started        75 4 other processes 51->75 71 conhost.exe 53->71         started        73 conhost.exe 53->73         started        77 6 other processes 53->77 79 10 other processes 55->79 process13 file14 118 C:\driverPerf\oKgiSMpZgyrXtIS.exe, PE32 61->118 dropped 120 C:\Windows\...\1wMVTjzOCfkSAncIabz.exe, PE32 61->120 dropped 122 C:\Users\user\Desktop\qCGvwgfL.log, PE32 61->122 dropped 124 9 other malicious files 61->124 dropped 204 Multi AV Scanner detection for dropped file 61->204 206 Drops executable to a common third party application directory 61->206 81 cmd.exe 61->81         started        signatures15 process16 signatures17 144 Wscript starts Powershell (via cmd or directly) 81->144 146 Uses ping.exe to sleep 81->146 148 Drops executables to the windows directory (C:\Windows) and starts them 81->148 150 3 other signatures 81->150 84 1wMVTjzOCfkSAncIabz.exe 81->84         started        88 conhost.exe 81->88         started        90 chcp.com 81->90         started        92 PING.EXE 81->92         started        process18 dnsIp19 132 723499cm.shnyash.ru 104.21.17.252, 49724, 49727, 49728 CLOUDFLARENETUS United States 84->132 134 172.67.178.244, 49764, 49765, 49766 CLOUDFLARENETUS United States 84->134 94 C:\Users\user\Desktop\wPwNjDiX.log, PE32 84->94 dropped 96 C:\Users\user\Desktop\pRINHoni.log, PE32 84->96 dropped 98 C:\Users\user\Desktop\oUhFloYo.log, PE32 84->98 dropped 100 3 other malicious files 84->100 dropped file20
Threat name:
Win32.Trojan.Uztuby
Status:
Malicious
First seen:
2025-04-10 20:29:56 UTC
File Type:
PE (Exe)
Extracted files:
17
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dcrat family:umbral family:xmrig family:xworm defense_evasion discovery execution infostealer miner persistence rat stealer trojan upx
Behaviour
Modifies data under HKEY_USERS
Modifies registry class
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Program Files directory
Drops file in Windows directory
Launches sc.exe
Drops file in System32 directory
Suspicious use of SetThreadContext
UPX packed file
Looks up external IP address via web service
Power Settings
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Creates new service(s)
Stops running service(s)
XMRig Miner payload
DcRat
Dcrat family
Detect Umbral payload
Detect Xworm Payload
Umbral
Umbral family
Xmrig family
Xworm
Xworm family
xmrig
Malware Config
C2 Extraction:
89.39.121.169:9000
Verdict:
Malicious
Tags:
Win.Trojan.Uztuby-9855059-0 external_ip_lookup dcrat
YARA:
n/a
Unpacked files
SH256 hash:
5fe3446e6ed09ff8b8dc0890888af2ca7bb4fa1acc5281acf64b5ef5d6420774
MD5 hash:
5e3da9cb266b107730f517d0f7db4954
SHA1 hash:
2641f306f1a766f26595b837754a5f04a7852e1c
SH256 hash:
08128d203d7b2ad934c65c6a3a37f682420413f37bbd69892cb5c415a19cef9a
MD5 hash:
06a902cd756a573dc09bf76f3957195c
SHA1 hash:
86f40cab568ea69b3c0f46ba0400a222f5fb9dd6
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24 INDICATOR_EXE_Packed_DotNetReactor
SH256 hash:
4fec95956088ca7dd2a5ff7f78d700e6a295cb3b5d1b4ac501b3b4055387b1dc
MD5 hash:
01183343f06cc6c92b270d6868b429c7
SHA1 hash:
c90b4e3d7355ce3b961f88a9c43ff75373300e91
SH256 hash:
67112216d099fbbbabb3ed3c59b4f7cca1c27bb99d8bd21941972e39c83888a2
MD5 hash:
a454094c7940f4389689cc7972619524
SHA1 hash:
77eb11200e3e6e7579e75c2fd1d15f4b0f169269
Detections:
UmbralStealer INDICATOR_SUSPICIOUS_EXE_SandboxUserNames INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice INDICATOR_SUSPICIOUS_EXE_SandboxComputerNames INDICATOR_SUSPICIOUS_EXE_SandboxSystemUUIDs MALWARE_Win_UmbralStealer
SH256 hash:
f1080146b6b4f53e2e9d46ffa8f17f1afefec5a982d25f1a49f8df4e33e0554d
MD5 hash:
cdfd2bee9fa26ef44ddac261cb0b83a9
SHA1 hash:
64aa0818a172d24e00c20dd1f223b4883e1f8dd4
Detections:
win_xworm_w0 XWorm win_xworm_bytestring win_mal_XWorm INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA MALWARE_Win_AsyncRAT MALWARE_Win_XWorm
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DotNet_Reactor
Author:@bartblaze
Description:Identifies .NET Reactor, which offers .NET code protection such as obfuscation, encryption and so on.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_EXE_Packed_DotNetReactor
Author:ditekSHen
Description:Detects executables packed with unregistered version of .NET Reactor
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MacOS_Cryptominer_Xmrig_241780a1
Author:Elastic Security
Rule name:MALWARE_Win_CoinMiner02
Author:ditekSHen
Description:Detects coinmining malware
Rule name:MAL_XMR_Miner_May19_1
Author:Florian Roth (Nextron Systems)
Description:Detects Monero Crypto Coin Miner
Reference:https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Rule name:MAL_XMR_Miner_May19_1_RID2E1B
Author:Florian Roth
Description:Detects Monero Crypto Coin Miner
Reference:https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:Mimikatz_Generic
Author:Still
Description:attempts to match all variants of Mimikatz
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PureCrypter
Author:@bartblaze
Description:Identifies PureCrypter, .NET loader and obfuscator.
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.purecrypter
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:rig_win64_xmrig_6_13_1_xmrig
Author:yarGen Rule Generator
Description:rig_win64 - file xmrig.exe
Reference:https://github.com/Neo23x0/yarGen
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:upx_largefile
Author:k3nr9
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Windows_Cryptominer_Generic_f53cfb9b
Author:Elastic Security
Rule name:XMRIG_Monero_Miner
Author:Florian Roth (Nextron Systems)
Description:Detects Monero mining software
Reference:https://github.com/xmrig/xmrig/releases
Rule name:xmrig_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

BlankGrabber

Executable exe 5fe3446e6ed09ff8b8dc0890888af2ca7bb4fa1acc5281acf64b5ef5d6420774

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdiplusShutdown
gdiplus.dll::GdipAlloc
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::AllocConsole
KERNEL32.dll::AttachConsole
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::FreeConsole
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateHardLinkW
KERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::MoveFileW
KERNEL32.dll::MoveFileExW

Comments