MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 664c8ea6640f0e3f8bd5ba3429656635d59f8272e37e0cdf646a1613efda9d8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AdaptixC2


Vendor detections: 14


Intelligence 14 IOCs YARA 1 File information Comments

SHA256 hash: 664c8ea6640f0e3f8bd5ba3429656635d59f8272e37e0cdf646a1613efda9d8f
SHA3-384 hash: ea215b771da43da1183eb76a84f4d38e68ff30e8721a58492fd8976bac2ec4cd8f7e3fc796b51a90e0681fbd6d6dfd20
SHA1 hash: 68a6877be539bdc70f6956c2b3f2aabe095b9d3a
MD5 hash: fe720b7550466baa14994a090eed156d
humanhash: hamper-south-white-connecticut
File name:fe720b7550466baa14994a090eed156d.exe
Download: download sample
Signature AdaptixC2
File size:94'208 bytes
First seen:2026-08-07 09:35:39 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 1536:p8Ji32GjqTUKc68n1TJRb0N3Q1q1FspS2tG9vPVSePGFhk9cY2du2EuymSvvtdvE:b2Ge9opS2QRk9wNhEn
TLSH T11C938335D3A3D0ADC45F8578AF9358B3A9F07C2C8630A235479966213B5FDB81FBA190
TrID 44.6% (.EXE) Win64 Executable (generic) (6522/11/2)
14.0% (.ICL) Windows Icons Library (generic) (2059/9)
13.8% (.EXE) OS/2 Executable (generic) (2029/13)
13.7% (.EXE) Generic Win/DOS Executable (2002/3)
13.6% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter abuse_ch
Tags:AdaptixC2 exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-07 09:41:45 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Connection attempt to an infection source
Sending a TCP request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 mingw packed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-05T07:14:00Z UTC
Last seen:
2026-08-05T10:09:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Infostealer.Tinba
Status:
Malicious
First seen:
2026-08-03 00:18:00 UTC
File Type:
PE+ (Exe)
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
664c8ea6640f0e3f8bd5ba3429656635d59f8272e37e0cdf646a1613efda9d8f
MD5 hash:
fe720b7550466baa14994a090eed156d
SHA1 hash:
68a6877be539bdc70f6956c2b3f2aabe095b9d3a
Detections:
win_adaptix_c2_a0 triage_adaptix_hacktool
Malware family:
AdaptixC2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments