🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 707f39f896c415ed170f2a5df48d334e8364f87a97ed9cfefe9f0ff4b0cc8a8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: 707f39f896c415ed170f2a5df48d334e8364f87a97ed9cfefe9f0ff4b0cc8a8c
SHA3-384 hash: a3334cc33cf207920670b1a13f55ce5c173faf26f84819fa3cb90b90052e82ec64d2ab3ceadba32dbeece77f37669fba
SHA1 hash: 40fea33b963afc4c79d102abe92a20d6eadb27bc
MD5 hash: bc242d88a1174757d343527df5bfeba9
humanhash: indigo-johnny-louisiana-timing
File name:707f39f896c415ed170f2a5df48d334e8364f87a97ed9cfefe9f0ff4b0cc8a8c.exe
Download: download sample
File size:3'718'034 bytes
First seen:2026-09-29 06:10:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (26 x ValleyRAT, 20 x OffLoader, 14 x Tofsee)
ssdeep 49152:4uI2h39ur4BpQ+440Qv5ScL5QOsnxiEz51oQaD1Hu8x/3ok9bz4pICVmkZ8662K:45OlGICk55giMYtn3bX493Z8gK
TLSH T11406F13FF18BA53EE06A163639B29210953BBA6164134C1796ECF88CCF255701E3E797
TrID 50.8% (.EXE) Inno Setup installer (107240/4/30)
20.4% (.EXE) InstallShield setup (43053/19/16)
19.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.0% (.EXE) Win64 Executable (generic) (6522/11/2)
2.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 5050d270cccc82ae (115 x Adware.Generic, 85 x OffLoader, 48 x ValleyRAT)
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
158
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-29 06:19:48 UTC
Tags:
delphi inno installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context crypto embarcadero_delphi fingerprint inno installer installer installer-heuristic packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-09-29T03:25:00Z UTC
Last seen:
2026-10-01T00:55:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
34 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Marsilia
Status:
Malicious
First seen:
2026-09-29 05:17:24 UTC
File Type:
PE (Exe)
Extracted files:
69
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks installed software on the system
Executes dropped EXE
Unpacked files
SH256 hash:
707f39f896c415ed170f2a5df48d334e8364f87a97ed9cfefe9f0ff4b0cc8a8c
MD5 hash:
bc242d88a1174757d343527df5bfeba9
SHA1 hash:
40fea33b963afc4c79d102abe92a20d6eadb27bc
SH256 hash:
6fdff7ad5c43a29aab872a6943f7e864cbe859251e6ef79654b430d93fb7d035
MD5 hash:
7cf9255e5a63308b89675b660de3ecf2
SHA1 hash:
fb6baf14b8b817984f93da60083f2e611ae9f0ec
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
SH256 hash:
22646861e5c88cd03424594313996a859944d16a71a198e3253e52b2c544261e
MD5 hash:
13dcc9bc2ab06b8979762d165a1af1ad
SHA1 hash:
c862d6222543ef84951ced7ac7926a23e33f51b8
SH256 hash:
fae2aa74d646662fad9d7c5c3ba03dbc6467814c40552b929f51fc21ef5766bf
MD5 hash:
34109159d8a19191c19d432e98a8e0f3
SHA1 hash:
f535535c9252071e1e63970e5d37f357a7cd8e28
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 707f39f896c415ed170f2a5df48d334e8364f87a97ed9cfefe9f0ff4b0cc8a8c

(this sample)

  
Delivery method
Distributed via web download

Comments