MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a0bf1dba11b61b4b53e78ccb483a7aea4ec3cfa81d2e7f9de55376c9fdef7ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: 6a0bf1dba11b61b4b53e78ccb483a7aea4ec3cfa81d2e7f9de55376c9fdef7ec
SHA3-384 hash: 249ce5466f24f730fc0528e82ed966d96356d64ae764d702a5f9488038c6a72acef38bc0d8eafa7ddb282dc678c6a72d
SHA1 hash: 8b0954a8e13c1086945b93e9e967786e86bd0f2a
MD5 hash: d9e0461524386292212444734e44619e
humanhash: ceiling-alabama-seventeen-mike
File name:d9e0461524386292212444734e44619e.exe
Download: download sample
Signature XWorm
File size:1'666'560 bytes
First seen:2026-06-22 14:42:57 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'144 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:Ot9gBVBCY/PqmhhDRDVAS6EeI6beY7xgfTIq+NQr7HBBhyb:ESCAymhhDRVgdx7xgsT8k
Threatray 228 similar samples on MalwareBazaar
TLSH T1497512AC3710F44FC9478A398670ED7496547DEA6307E20396D32EEF791E69ACE050E2
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon a55aa55aa55aa55a (3 x Formbook, 2 x RemcosRAT, 2 x PhantomStealer)
Reporter abuse_ch
Tags:exe xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
SE SE
Vendor Threat Intelligence
Malware configuration found for:
ConfuserEx RoboSki
Details
Malware family:
n/a
ID:
1
File name:
_6a0bf1dba11b61b4b53e78ccb483a7aea4ec3cfa81d2e7f9de55376c9fdef7ec.exe
Verdict:
Malicious activity
Analysis date:
2026-06-22 14:45:04 UTC
Tags:
auto-reg netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
81.4%
Tags:
stration shell spawn
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Connection attempt
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated obfuscated packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-06-21T12:12:00Z UTC
Last seen:
2026-06-23T23:27:00Z UTC
Hits:
~100
Detections:
Trojan-Dropper.Scrop.HTTP.C&C PDM:Trojan.Win32.Generic Trojan.Win32.Agent.sb Trojan.MSIL.Inject.sb HEUR:Backdoor.MSIL.Remcos.gen Trojan.MSIL.Dnoper.sb Trojan-PSW.Stealer.HTTP.C&C
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected AntiVM3
Yara detected MSIL Injector
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1931905 Sample: dON4IQKgqe.exe Startdate: 22/06/2026 Architecture: WINDOWS Score: 100 60 Malicious sample detected (through community Yara rule) 2->60 62 Antivirus / Scanner detection for submitted sample 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 12 other signatures 2->66 7 dON4IQKgqe.exe 1 7 2->7         started        11 powershell.exe 19 2->11         started        13 fSmFLvrjkQfOLb.exe 2->13         started        15 2 other processes 2->15 process3 file4 46 C:\Users\user\AppData\...\fSmFLvrjkQfOLb.exe, PE32 7->46 dropped 48 C:\...\fSmFLvrjkQfOLb.exe:Zone.Identifier, ASCII 7->48 dropped 50 C:\Users\user\AppData\...\cmc2tgppksy.ps1, ASCII 7->50 dropped 52 C:\Users\user\AppData\...\dON4IQKgqe.exe.log, ASCII 7->52 dropped 78 Detected unpacking (changes PE section rights) 7->78 80 Detected unpacking (overwrites its own PE header) 7->80 82 Creates autostart registry keys with suspicious values (likely registry only malware) 7->82 84 Creates an autostart registry key pointing to binary in C:\Windows 7->84 17 dON4IQKgqe.exe 15 2 7->17         started        21 powershell.exe 23 7->21         started        23 fSmFLvrjkQfOLb.exe 5 11->23         started        26 conhost.exe 11->26         started        86 Adds a directory exclusion to Windows Defender 13->86 88 Injects a PE file into a foreign processes 13->88 28 powershell.exe 13->28         started        36 2 other processes 13->36 30 fSmFLvrjkQfOLb.exe 15->30         started        32 conhost.exe 15->32         started        34 conhost.exe 15->34         started        signatures5 process6 dnsIp7 58 31.56.36.228, 443, 49696, 49703 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 17->58 68 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 17->68 70 Loading BitLocker PowerShell Module 21->70 38 conhost.exe 21->38         started        54 C:\Windows\Temp\tr30cdip.inf, Windows 23->54 dropped 72 Antivirus detection for dropped file 23->72 74 Multi AV Scanner detection for dropped file 23->74 76 Adds a directory exclusion to Windows Defender 23->76 40 cmstp.exe 23->40         started        42 conhost.exe 28->42         started        56 C:\Windows\Temp\xhoysnw5.inf, Windows 30->56 dropped 44 cmstp.exe 30->44         started        file8 signatures9 process10
Gathering data
Threat name:
ByteCode-MSIL.Trojan.LummaStealer
Status:
Malicious
First seen:
2026-06-20 00:25:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
25 of 38 (65.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
6a0bf1dba11b61b4b53e78ccb483a7aea4ec3cfa81d2e7f9de55376c9fdef7ec
MD5 hash:
d9e0461524386292212444734e44619e
SHA1 hash:
8b0954a8e13c1086945b93e9e967786e86bd0f2a
SH256 hash:
17f08a6524850356522e1cf34b1d40ac71e79311612d7f5c2c6be840c35b6c16
MD5 hash:
37a16a468be2ff4f499c47c53e8d40b8
SHA1 hash:
18338aeaa2f4e4571bdcd31341d2ac65dbd954e1
SH256 hash:
2f793a7e46c0c3ce03e0861700921c2b0f8b268a08daff9f7f872613321439ac
MD5 hash:
88ac272696f28035da8d31a7111e8f49
SHA1 hash:
5d1a6708ae121afb37b7ee43a50b8588801234a9
SH256 hash:
9a963bc2f76ecd2892f79895ca6d6787eb606cdc2e7ae5a0ec0f2fba48700fb1
MD5 hash:
4701cc6fa427e61852a78a967a0a29db
SHA1 hash:
fdc4b8a22459ec777dc1a9708a09e66c32869a09
SH256 hash:
e9a9fb19aa7ed893787ff7c9dde2aa3b68ac2993ce66a0455885db6a72216748
MD5 hash:
17250b5e2db2360085462516e3f601a4
SHA1 hash:
3c32a0e89d750f6b9499c6958afd7944857fe53d
SH256 hash:
b2a66e9864f81c2800a5afef4bfd1faf7c910e5a43ea2eb9dbb15c8ab6ffc633
MD5 hash:
f0a13fb422cdb1f3ce667df897b5045b
SHA1 hash:
9b6566603e3a292482788924a83a1d94a9cd4627
SH256 hash:
d4e4ce67ee8ed21857a3e8a7649768617269dca3b83ca4919a517c3055b46cc8
MD5 hash:
fa332a56b3d9b4cfba770588fea75436
SHA1 hash:
c7a422d71c389ed8c48f3312957669764905c374
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments