MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64d5e1a8c75834211dd8bcfbaab00b87b5a85cf8db3108922bd25f84d5ee229f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 7 File information Comments

SHA256 hash: 64d5e1a8c75834211dd8bcfbaab00b87b5a85cf8db3108922bd25f84d5ee229f
SHA3-384 hash: f8141b6abd9257fcf28ebcc4f181660743bef6c547a6cdc21421a3c8e07bd15d888a8c014cf049cc65aa50733c4a253f
SHA1 hash: 7258e79ade67f5a61452625f292a9eea54008922
MD5 hash: e672df73c4637a226aa17af0cda2157c
humanhash: king-berlin-sixteen-one
File name:svc.exe
Download: download sample
File size:15'836'539 bytes
First seen:2026-08-16 18:00:40 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash cf72283be50852e418ce6bbb6b645835 (101 x Efimer, 32 x Adware.Yogi, 8 x BlankGrabber)
ssdeep 393216:E85vzvLoWdQ2l6+9JgLaeFpWpTfuADKc/wuRz:n5vzvLoWdQm9JRe6nDSS
TLSH T1B1F63396620814D7C9A301B6D2D7C034DB22BE669BB0E2DF4BE066131DAB7E41D37F16
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon c6c2ccc4f4e0e0f8 (49 x PythonStealer, 32 x Adware.Yogi, 29 x SVCStealer)
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
IN IN
Vendor Threat Intelligence
Malware configuration found for:
PyInstaller
Details
Malware family:
n/a
ID:
1
File name:
http://93.152.223.228/svc.exe
Verdict:
No threats detected
Analysis date:
2026-08-16 17:56:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Creating a window
Running batch commands
Creating a process with a hidden window
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Searching for the window
Using the Windows Management Instrumentation requests
Creating a file
Reading critical registry keys
Launching a tool to kill processes
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-16T16:19:00Z UTC
Last seen:
2026-08-16T16:43:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-16 17:32:33 UTC
File Type:
PE+ (Exe)
Extracted files:
1327
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution pyinstaller spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Kills process with taskkill
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Views/modifies file attributes
Browser Information Discovery
Executes a command shell one-liner
System Time Discovery
Hide Artifacts: Hidden Files and Directories
Looks up external IP address via web service
Loads dropped DLL
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
64d5e1a8c75834211dd8bcfbaab00b87b5a85cf8db3108922bd25f84d5ee229f
MD5 hash:
e672df73c4637a226aa17af0cda2157c
SHA1 hash:
7258e79ade67f5a61452625f292a9eea54008922
SH256 hash:
76fdb83fde238226b5bebaf3392ee562e2cb7ca8d3ef75983bf5f9d6c7119644
MD5 hash:
870fea4e961e2fbd00110d3783e529be
SHA1 hash:
a948e65c6f73d7da4ffde4e8533c098a00cc7311
SH256 hash:
fc17eb621ecf2325e3c2d7501d3ee2c3848e3c7fec7027fda7c7fa1782874743
MD5 hash:
48939ec66bb9a4902acad835092465eb
SHA1 hash:
f1e10d14eb294eb70583b5019b52102a74ae6d7c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PyInstaller
Author:@bartblaze
Description:Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 64d5e1a8c75834211dd8bcfbaab00b87b5a85cf8db3108922bd25f84d5ee229f

(this sample)

  
Delivery method
Distributed via web download

Comments