MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 629cfb8d9fcb99aa0083415da49692ce4c94ecf01ed173e628a8ea8a9d4a5cf9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.iWin


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 629cfb8d9fcb99aa0083415da49692ce4c94ecf01ed173e628a8ea8a9d4a5cf9
SHA3-384 hash: 9c075b58d2411d445b40589848a57707bfbe84ee3cfe7b8a95e9a206bfb2c09420210911b3ed53b932054764cefd5f53
SHA1 hash: 7820a8f3ce9ca53b0cb30e0aca27ef407de0608e
MD5 hash: 9777f980cd8762d7253e4cc776dda7c0
humanhash: violet-washington-north-montana
File name:WatchForParty Setup 1.2.0.exe
Download: download sample
Signature Adware.iWin
File size:83'469'408 bytes
First seen:2026-08-09 21:46:49 UTC
Last seen:2026-08-10 12:54:39 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:eb2um4Ndc2Vq4ujn8KOY8ZwK1JIr+c3O7qYzhdhPtGwaK2Q+EdPpXt:ebTm4PHq4uj8A8ZwewNgqYtT0FKN/Xt
TLSH T1B9083336AAF13470C7C58E321A1555A3009DE18F51977E78B379B27FA21A281C2C6FED
TrID 27.0% (.EXE) Win64 Executable (generic) (6522/11/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.4% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon f8f0c6e8b886ccf0 (1 x Adware.iWin)
Reporter JaffaCakes118
Tags:Adware.iWin exe signed

Code Signing Certificate

Organisation:MyCompany
Issuer:MyCompany
Algorithm:sha256WithRSAEncryption
Valid from:2026-08-01T11:08:44Z
Valid to:2031-08-01T11:18:38Z
Serial number: 1a01e432a40237b849eb2d2f5ca56de5
Thumbprint Algorithm:SHA256
Thumbprint: b3c852ee1650ea4985c9926a0aa189c9647aab77e3b200276144dccdd4e298ee
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
504
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-09 21:55:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Searching for synchronization primitives
Searching for the window
Launching a service
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context adaptive-context anti-debug anti-vm fingerprint installer installer keylogger microsoft_visual_cc nsis packed reconnaissance signed
Verdict:
Unknown
File Type:
exe x32
First seen:
2026-08-07T05:35:00Z UTC
Last seen:
2026-08-07T07:23:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-05 00:47:22 UTC
File Type:
PE (Exe)
Extracted files:
7523
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution spyware stealer
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Hide Artifacts: Ignore Process Interrupts
Executes a VBScript file via the Windows Script Host.
Checks installed software on the system
Command and Scripting Interpreter: PowerShell
Contacts third-party web service commonly abused for C2
Obfuscated Files or Information: Command Obfuscation
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Adware.iWin

Executable exe 629cfb8d9fcb99aa0083415da49692ce4c94ecf01ed173e628a8ea8a9d4a5cf9

(this sample)

  
Delivery method
Distributed via web download

Comments