🀲🏼 NEW | abuse.ch Community Hub! Earn recognition πŸ… for the malware intelligence you share, climb the leaderboards πŸ“ˆ, and connect with like-minded contributors who share your hunting focus 🀝. Ready to unlock your profile? Go to the Community Hub β†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 643458abc17da13200343c39fb728ed98691f4e09583156124c19958bf04bd75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 10 File information Comments

SHA256 hash: 643458abc17da13200343c39fb728ed98691f4e09583156124c19958bf04bd75
SHA3-384 hash: 099e351d0a86498a51950790ab92cd2650109e2c906e851eb45e4de66e663e70a832b6d0b488ebdde3207f646a554280
SHA1 hash: c4c84977c6326421601f0e4b2e141a8d03fa8b3d
MD5 hash: 9d1eaa9147eb5865fa5c9978ff1b7078
humanhash: mirror-violet-idaho-grey
File name:2133.exe
Download: download sample
File size:162'720 bytes
First seen:2026-09-18 20:49:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0c75a978e52c593c4e2514d223cf2880
ssdeep 3072:iRBjs0JWIK1GYp2w6lRituRA6nPoY4ciMK4nNq/1GW:cFcIwGYPSituRAqohx4Q/J
TLSH T1C3F35B07B6AA30F9E472C53488912616FB72B87103359B7F47A047765F237A0AD3EB61
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter devmihaylov
Tags:7moor Certum Downloader exe signed stager

Code Signing Certificate

Organisation:上ι₯ΆεΈ‚ε˜‰η«―η§‘ζŠ€ζœ‰ι™ε…¬εΈ
Issuer:Certum Extended Validation Code Signing 2021 CA
Algorithm:sha256WithRSAEncryption
Valid from:2026-08-13T13:21:17Z
Valid to:2027-08-13T13:21:16Z
Serial number: 5250ab4dd4bd6312f22f92e9b40d8e05
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 6588eaf3a40f60024d7e6f565b8bb2f1d62336c6f4e80e4c5b96a5dbba514a71
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
devmihaylov
Certum EV-signed 64-bit downloader with no strings, hand-resolved ntdll natives, a mouse-presence gate and runas self-elevation, which fetches an RC4-hidden URL and runs the XOR-decoded response as in-process shellcode. Second stage not obtained, the CDN answers 514 with an empty body.

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
BG BG
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
8887.exe
Verdict:
No threats detected
Analysis date:
2026-09-18 09:31:39 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm explorer lolbin microsoft_visual_cc signed
Verdict:
Unknown
File Type:
exe x64
First seen:
2026-09-18T05:35:00Z UTC
Last seen:
2026-09-19T03:17:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Wacatac
Status:
Suspicious
First seen:
2026-09-18 12:29:11 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
643458abc17da13200343c39fb728ed98691f4e09583156124c19958bf04bd75
MD5 hash:
9d1eaa9147eb5865fa5c9978ff1b7078
SHA1 hash:
c4c84977c6326421601f0e4b2e141a8d03fa8b3d
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:certum_issuer
Author:Certum
Description:Looks for files signed with certificate issued by Certum
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:detect_certum_issuer
Author:Certum
Description:Looks for files signed with certificate issued by Certum
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments