🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 624f37b4ad2253bc5f87bf8c1923e3c78bf81f8c0f97188d876f806b3fbdc691. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 14


Intelligence 14 IOCs YARA 6 File information Comments

SHA256 hash: 624f37b4ad2253bc5f87bf8c1923e3c78bf81f8c0f97188d876f806b3fbdc691
SHA3-384 hash: d096d218da660b0e7911717587c3523d3fee1a6c4d2419db26c178cc73aa9acd8f10809e8c45e59e8342507b40c2a145
SHA1 hash: 212aa6dd5b118910e424d59a96a6a3f979646c83
MD5 hash: 331906314e39f236039f1cf09c8d7859
humanhash: solar-william-victor-summer
File name:fres.exe
Download: download sample
File size:118'272 bytes
First seen:2025-12-14 20:11:41 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2c5f2513605e48f2d8ea5440a870cb9e (62 x Babadeda, 7 x CoinMiner, 6 x AveMariaRAT)
ssdeep 3072:+7DhdC6kzWypvaQ0FxyNTBf3rsqSvCOFK/:+BlkZvaF4NTB/rsqSvrE/
Threatray 3'098 similar samples on MalwareBazaar
TLSH T1FFC39E41F2E242F7E6E2057100B6752F9736B3388734A8EBC74C2E525A13AD5963D3E9
TrID 36.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
19.5% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.4% (.EXE) Win64 Executable (generic) (10522/11/4)
7.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
5.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter Anonymous
Tags:exe ransomeware-like Updater WannaCry


Avatar
Anonymous
This looks like some kind of fake ransomware like Wannacry or Updater.

Intelligence


File Origin
# of uploads :
1
# of downloads :
241
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
BatToExeConverter
Details
BatToExeConverter
an RC4 decrypted batch script or command line
Malware family:
n/a
ID:
1
File name:
fres.exe
Verdict:
Suspicious activity
Analysis date:
2025-12-14 20:12:46 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
shell sage blic
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bat_to_exe_converter packed packed purebasic
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-12-14T17:26:00Z UTC
Last seen:
2025-12-14T17:57:00Z UTC
Hits:
~10
Detections:
Worm.BAT.Agent.el Trojan-Ransom.Win32.Agent.sb HEUR:Trojan.BAT.Formatter.gen
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.LShot
Status:
Malicious
First seen:
2025-12-14 20:12:16 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Runs net.exe
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Verdict:
Malicious
Tags:
trojan
YARA:
SUSP_Imphash_Mar23_3
Unpacked files
SH256 hash:
624f37b4ad2253bc5f87bf8c1923e3c78bf81f8c0f97188d876f806b3fbdc691
MD5 hash:
331906314e39f236039f1cf09c8d7859
SHA1 hash:
212aa6dd5b118910e424d59a96a6a3f979646c83
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:PureBasic4xNeilHodgson
Author:malware-lu
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SUSP_Imphash_Mar23_3
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Multiple

Comments