MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63c128dcb78f5ea819596b684e596f4d43be3178ea3f5c58800eba9e1d008d40. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 63c128dcb78f5ea819596b684e596f4d43be3178ea3f5c58800eba9e1d008d40
SHA3-384 hash: 037615baf599c51c992d810e8b7f2fa53917f67ed75eb93d800456f5c3ee92f7b9331fee3659cb1b3f5630af834f8b73
SHA1 hash: 32709b04f7994c96545c42fb3402b7479fea8543
MD5 hash: 92fbea8a8e0f5dec6269c1f00e08236e
humanhash: neptune-lamp-ink-lion
File name:file
Download: download sample
File size:2'293'248 bytes
First seen:2026-08-29 04:27:27 UTC
Last seen:2026-08-29 05:46:57 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5192a4c65487ec8ce4c7e38ef81eb8b4
ssdeep 49152:oOUgKnTfeVkyKiuzBNpNmoLxDXo1ydvKMAGrFAyB:03Tg+1NmMxXo1eKIJxB
TLSH T126B58CB24B57E263C8080935332CDEBC2D02E9A7237172D036D76FAD21E15ED9676AD1
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-gcleaner exe G US0.file


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
2
# of downloads :
201
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-29 04:34:57 UTC
Tags:
pdfwkrnl-sys vuln-driver

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a process with a hidden window
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Creating a file in the %temp% directory
Creating a file in the Windows subdirectories
Creating a service
Launching a service
Loading a system driver
Enabling autorun for a service
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug mingw overlay packed reconnaissance
Verdict:
Adware
File Type:
exe x64
First seen:
2026-08-29T02:46:00Z UTC
Last seen:
2026-08-30T21:38:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-29 04:28:22 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes dropped EXE
Unpacked files
SH256 hash:
63c128dcb78f5ea819596b684e596f4d43be3178ea3f5c58800eba9e1d008d40
MD5 hash:
92fbea8a8e0f5dec6269c1f00e08236e
SHA1 hash:
32709b04f7994c96545c42fb3402b7479fea8543
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 63c128dcb78f5ea819596b684e596f4d43be3178ea3f5c58800eba9e1d008d40

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments