MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 62fa24c9f3f0cb8f0ef411ecd4d0939e775bcbadc30ae8a0ac4e999dae049dbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MyDoom


Vendor detections: 15


Intelligence 15 IOCs YARA 3 File information Comments

SHA256 hash: 62fa24c9f3f0cb8f0ef411ecd4d0939e775bcbadc30ae8a0ac4e999dae049dbb
SHA3-384 hash: e16d25bf000d8f3ba9d8a2e7827bdf3b96d6d1832b912ef769adf639895ea35edc2a4eba9d7c4c0101f8745b6d563313
SHA1 hash: dc845713ee9669971e967f0f68546be718e5bc25
MD5 hash: d121235211b62df289ee961414e06fa4
humanhash: delta-autumn-snake-jig
File name:README.PIF
Download: download sample
Signature MyDoom
File size:28'864 bytes
First seen:2026-07-23 05:53:38 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 98cd465c2ab2841f9fd90d5e847563f4 (46 x MyDoom)
ssdeep 384:1vxBbK26lj5Id8SpHx9jLhsznnVxA1WmP5w7GGCJlqqwMyNfc+p:Dv8IRRdsxq1DjJcqf0f
TLSH T140D2D085B050B6A3C05682731D86C461FD029C641A9AC2DB7664BF7FFDF17864B0CD2B
TrID 34.7% (.EXE) UPX compressed Win32 Executable (27066/9/6)
34.1% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
8.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.7% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b270e0d292c0c482 (83 x MyDoom)
Reporter lowmal3
Tags:exe Mydoom UPX
File size (compressed) :28'864 bytes
File size (de-compressed) :41'664 bytes
Format:win32/pe
Unpacked file: 602cc7985ad5a2a05425cfa1b16aa7a6e00165455a6d6566234141bc787ff8e9

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file in the Windows directory
Creating a process from a recently created file
Creating a process with a hidden window
Searching for the window
Connection attempt
Creating a window
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug bankingtrojan masquerade overlay packed packed packed packer reconnaissance upx xor-pe
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-23T03:37:00Z UTC
Last seen:
2026-07-23T11:59:00Z UTC
Hits:
~10
Result
Threat name:
Detection:
malicious
Classification:
spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops executables to the windows directory (C:\Windows) and starts them
Drops PE files with benign system names
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Yara detected MyDoom
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1946918 Sample: README.PIF.exe Startdate: 23/07/2026 Architecture: WINDOWS Score: 100 39 Antivirus / Scanner detection for submitted sample 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 Yara detected MyDoom 2->43 45 4 other signatures 2->45 6 java.exe 1 2->6         started        10 README.PIF.exe 1 5 2->10         started        12 services.exe 2->12         started        process3 file4 25 C:\Users\user\AppData\Local\...\services.exe, PE32 6->25 dropped 47 Antivirus detection for dropped file 6->47 49 Multi AV Scanner detection for dropped file 6->49 51 Exploit detected, runtime environment starts unknown processes 6->51 53 Exploit detected, runtime environment dropped PE file 6->53 14 services.exe 6->14         started        27 C:\Windows\services.exe, PE32 10->27 dropped 29 C:\Windows\java.exe, PE32 10->29 dropped 31 C:\Windows\java.exe:Zone.Identifier, ASCII 10->31 dropped 55 Drops executables to the windows directory (C:\Windows) and starts them 10->55 57 Drops PE files with benign system names 10->57 17 services.exe 1 1 10->17         started        20 WerFault.exe 21 16 10->20         started        signatures5 process6 dnsIp7 33 67.201.226.55, 1034 WWU-WesternWashingtonUniversityUS United States 17->33 35 4.240.78.20, 1034 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS India 17->35 37 5 other IPs or domains 17->37 59 Antivirus detection for dropped file 17->59 61 Multi AV Scanner detection for dropped file 17->61 23 C:\ProgramData\Microsoft\...\Report.wer, Unicode 20->23 dropped file8 signatures9
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Worm.Mydoom
Status:
Malicious
First seen:
2026-07-23 05:54:39 UTC
File Type:
PE (Exe)
Extracted files:
11
AV detection:
24 of 24 (100.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mydoom discovery persistence upx worm
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Drops file in Windows directory
UPX packed file
Adds Run key to start application
Executes dropped EXE
Detects MyDoom family
Family: MyDoom
Unpacked files
SH256 hash:
62fa24c9f3f0cb8f0ef411ecd4d0939e775bcbadc30ae8a0ac4e999dae049dbb
MD5 hash:
d121235211b62df289ee961414e06fa4
SHA1 hash:
dc845713ee9669971e967f0f68546be718e5bc25
SH256 hash:
c636062f0163282e57721d265d9f7696bc2bcb37133150be559a51ccd35ed61d
MD5 hash:
e89740d44d165a2a6557b48be16e15a8
SHA1 hash:
a2b0d6a77a83f6f855b2c75193bc9d0d65e64fbe
Detections:
MyDoom
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:upx_3
Author:Kevin Falcoz
Description:UPX 3.X
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

MyDoom

Executable exe 62fa24c9f3f0cb8f0ef411ecd4d0939e775bcbadc30ae8a0ac4e999dae049dbb

(this sample)

Comments