MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GhostPulse


Vendor detections: 18


Intelligence 18 IOCs YARA 5 File information Comments

SHA256 hash: 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8
SHA3-384 hash: a82e86c94a388d1a83da8eeeefcb34cdcd026aa893b70556c443122f5c4875a7e2c56ba985f4bbf5578bea8842eee57b
SHA1 hash: 0307b9ea1e3f916e0f247cdb004cbe792d32fd9f
MD5 hash: 99f942f227f3c7595840593c1a77e5b1
humanhash: spaghetti-batman-angel-glucose
File name:INUS.exe
Download: download sample
Signature GhostPulse
File size:7'212'968 bytes
First seen:2026-05-28 23:53:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b5a014d7eeb4c2042897567e1288a095 (24 x HijackLoader, 23 x GhostPulse, 14 x ValleyRAT)
ssdeep 196608:+p8VXfNsbQPOSPyKxfKj37C5s6wxgqixWkSLFBVfvHaciH9:+p8VXf6bONPyA037C5waqgEl/Ud
Threatray 104 similar samples on MalwareBazaar
TLSH T1AC76334637A478FED939C0B28F1DC7A99732EA7412414DCB509C5F6B2EA7A2103DB1C9
TrID 42.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
16.8% (.EXE) Win64 Executable (generic) (6522/11/2)
13.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon c292ecd8f2f6fe1c (23 x GhostPulse, 23 x HijackLoader, 11 x LummaStealer)
Reporter aachum
Tags:66-163-113-238 cloud55file-cc exe GhostPulse HIjackLoader SnappyClient vidar YodaTeam


Avatar
iamaachum
http://cloud55file.cc/load/os1/INUS.exe

Vidar C2: https://65.109.250.21/

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
kythy.exe
Verdict:
Malicious activity
Analysis date:
2026-05-28 23:06:12 UTC
Tags:
ip-check evasion loader generic golang stealer hijackloader auto-startup stealc vidar python

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
autorun lien
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Creating a file in the %AppData% subdirectories
Using the Windows Management Instrumentation requests
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Reading critical registry keys
Transferring files using the Background Intelligent Transfer Service (BITS)
Enabling the 'hidden' option for recently created files
Unauthorized injection to a recently created process by context flags manipulation
Stealing user critical data
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context evasive fingerprint installer installer installer-heuristic microsoft_visual_cc overlay packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-28T21:40:00Z UTC
Last seen:
2026-05-30T07:52:00Z UTC
Hits:
~100
Detections:
Trojan-PSW.Win32.Stealer.sb Trojan-Banker.Win32.ClipBanker.sb Trojan.Win32.Inject.sb Trojan.Win32.Zenpak.sb Trojan.Win32.Penguish.hna Trojan-PSW.Stealerc.TCP.C&C Trojan-PSW.Stealerc.HTTP.ServerRequest Trojan-PSW.Stealerc.HTTP.C&C Trojan.Win32.Strab.sb Trojan.Win32.Penguish.sb Trojan.Win32.Agent.sb
Result
Threat name:
HijackLoader, SnappyClient, Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Contains VNC / remote desktop functionality (version string found)
Creates a thread in another existing process (thread injection)
Drops PE files to the user root directory
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Query firmware table information (likely to detect VMs)
Queues an APC in another process (thread injection)
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Unusual module load detection (module proxying)
Yara detected HijackLoader
Yara detected SnappyClient
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1920078 Sample: INUS.exe Startdate: 29/05/2026 Architecture: WINDOWS Score: 100 130 yoda.nepaltathya.com 2->130 132 yoda-vac.online 2->132 134 5 other IPs or domains 2->134 154 Suricata IDS alerts for network traffic 2->154 156 Found malware configuration 2->156 158 Multi AV Scanner detection for submitted file 2->158 160 4 other signatures 2->160 11 INUS.exe 9 2->11         started        14 msedge.exe 2->14         started        17 msedge.exe 2->17         started        signatures3 process4 dnsIp5 104 C:\Users\user\AppData\...\vstdlib_s64.dll, PE32+ 11->104 dropped 106 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32+ 11->106 dropped 108 C:\Users\user\AppData\Local\...\tier0_s64.dll, PE32+ 11->108 dropped 114 2 other malicious files 11->114 dropped 19 Vect_P16.exe 8 11->19         started        152 239.255.255.250 unknown ZZ 14->152 110 C:\Users\user\AppData\Local\...\Login Data, SQLite 14->110 dropped 112 C:\Users\user\AppData\Local\...\History, SQLite 14->112 dropped 23 msedge.exe 14->23         started        25 msedge.exe 14->25         started        28 msedge.exe 14->28         started        30 msedge.exe 17->30         started        32 msedge.exe 17->32         started        34 msedge.exe 17->34         started        file6 process7 dnsIp8 80 C:\ProgramData\...\Vect_P16.exe, PE32+ 19->80 dropped 82 C:\ProgramData\...\vstdlib_s64.dll, PE32+ 19->82 dropped 84 C:\ProgramData\...\ucrtbase.dll, PE32+ 19->84 dropped 88 2 other files (none is malicious) 19->88 dropped 162 Found hidden mapped module (file has been removed from disk) 19->162 164 Switches to a custom stack to bypass stack traces 19->164 166 Found direct / indirect Syscall (likely to bypass EDR) 19->166 36 Vect_P16.exe 15 19->36         started        40 Vect_P16.exe 23->40         started        136 ax-0002.ax-msedge.net 150.171.27.11, 443, 49741 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 25->136 138 bx-0004.bx-msedge.net 150.171.73.13, 443, 49742, 49743 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 25->138 144 5 other IPs or domains 25->144 86 C:\Users\user\AppData\Local\...\Cookies, SQLite 25->86 dropped 140 mr-afd-azuredge.tm-azurefd.net 150.171.110.1, 443, 49758, 49759 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 30->140 142 ln-0007.ln-msedge.net 150.171.22.17, 443, 49751 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 30->142 146 4 other IPs or domains 30->146 file9 signatures10 process11 file12 90 C:\Users\user\RippleTr.exe, PE32+ 36->90 dropped 92 C:\Users\user\AppData\...\vstdlib_s64.dll, PE32+ 36->92 dropped 94 C:\Users\user\AppData\...\ucrtbase.dll, PE32+ 36->94 dropped 102 5 other malicious files 36->102 dropped 168 Drops PE files to the user root directory 36->168 170 Modifies the context of a thread in another process (thread injection) 36->170 172 Found hidden mapped module (file has been removed from disk) 36->172 176 2 other signatures 36->176 42 RippleTr.exe 1 15 36->42         started        47 Vect_P16.exe 7 36->47         started        49 Crisp.exe 36->49         started        96 C:\Users\user\AppData\Roaming\...\Crisp.exe, PE32 40->96 dropped 98 C:\Users\user\AppData\Local\...\7ED70CF.tmp, PE32+ 40->98 dropped 100 C:\ProgramData\CascadeNavigat128.exe, PE32+ 40->100 dropped 174 Maps a DLL or memory area into another process 40->174 51 CascadeNavigat128.exe 40->51         started        53 Crisp.exe 40->53         started        signatures13 process14 dnsIp15 148 65.109.250.21, 443, 49721, 49722 HETZNER-ASDE Finland 42->148 150 yoda.nepaltathya.com 172.67.216.168, 443, 49775 CLOUDFLARENET-CloudflareIncUS Canada 42->150 116 C:\Users\user\AppData\Local\...\ec4ad30f.exe, PE32 42->116 dropped 190 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 42->190 192 Found many strings related to Crypto-Wallets (likely being stolen) 42->192 194 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 42->194 206 5 other signatures 42->206 55 cmd.exe 42->55         started        57 msedge.exe 2 11 42->57         started        60 msedge.exe 42->60         started        62 chrome.exe 42->62         started        118 C:\Users\user\AppData\Roaming\...\Crisp.exe, PE32 47->118 dropped 120 C:\Users\user\AppData\Local\...\53E578F.tmp, PE32 47->120 dropped 122 C:\ProgramData\ZTracker32.exe, PE32 47->122 dropped 196 Found hidden mapped module (file has been removed from disk) 47->196 198 Maps a DLL or memory area into another process 47->198 200 Switches to a custom stack to bypass stack traces 47->200 64 ZTracker32.exe 5 47->64         started        67 Crisp.exe 3 47->67         started        202 Unusual module load detection (module proxying) 49->202 204 Tries to harvest and steal browser information (history, passwords, etc) 51->204 file16 signatures17 process18 dnsIp19 69 ec4ad30f.exe 55->69         started        72 conhost.exe 55->72         started        180 Monitors registry run keys for changes 57->180 74 msedge.exe 57->74         started        76 msedge.exe 60->76         started        78 chrome.exe 62->78         started        124 example.com 104.20.23.154, 49719, 49724, 49750 CLOUDFLARENET-CloudflareIncUS Canada 64->124 126 172.66.147.243, 49784, 49786, 49788 CLOUDFLARENET-CloudflareIncUS Canada 64->126 128 yoda-line.site 66.163.113.238, 3333, 49718, 49720 AS-GLOBALTELEHOST-GLOBALTELEHOSTCorpCA Canada 64->128 182 Query firmware table information (likely to detect VMs) 64->182 184 Contains VNC / remote desktop functionality (version string found) 64->184 186 Unusual module load detection (module proxying) 64->186 188 Switches to a custom stack to bypass stack traces 67->188 signatures20 process21 signatures22 178 Multi AV Scanner detection for dropped file 69->178
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-28 23:53:48 UTC
File Type:
PE (Exe)
Extracted files:
41
AV detection:
13 of 23 (56.52%)
Threat level:
  5/5
Result
Malware family:
snappyclient
Score:
  10/10
Tags:
family:hijackloader family:snappyclient backdoor credential_access discovery loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Drops desktop.ini file(s)
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Detects HijackLoader (aka IDAT Loader)
Family: HijackLoader, IDAT loader, Ghostulse,
Family: SnappyClient
Suspicious use of NtCreateProcessExOtherParentProcess
Unpacked files
SH256 hash:
642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8
MD5 hash:
99f942f227f3c7595840593c1a77e5b1
SHA1 hash:
0307b9ea1e3f916e0f247cdb004cbe792d32fd9f
SH256 hash:
0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba
MD5 hash:
fd3ce044ac234fdab3df9d7f492c470a
SHA1 hash:
a74a287d5d82a8071ab36c72b2786342d83a8ef7
SH256 hash:
2a7825c2925347e0cb767a0dcb611f3eb80d0f71cbec981069b227bdc7cb871a
MD5 hash:
ec9f1cdd909f7c0bae4db21dcd2033de
SHA1 hash:
4c2a112e048fc75cd4c581836356e881552c9be2
Malware family:
HijackLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GhostPulse

Executable exe 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8

(this sample)

  
Delivery method
Distributed via web download

Comments