🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70b6b983b1d9e90206328dbdea8f044682e1be807ec6e9c71dcd0cd76f3dbe9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 12 File information Comments

SHA256 hash: 70b6b983b1d9e90206328dbdea8f044682e1be807ec6e9c71dcd0cd76f3dbe9c
SHA3-384 hash: a550439ab613408f76f7290a413fd201d5698cb4cfe3d721c5564eb800119ab1583fd38c190feb6813fe50e07a763591
SHA1 hash: 4f396620696537410eaf6e9438c3b07ab0099d37
MD5 hash: 162c454c5a8ec5d998119b606d234000
humanhash: magazine-cat-snake-lithium
File name:kbvsxhrs.exe
Download: download sample
File size:793'600 bytes
First seen:2026-09-25 02:49:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e49e29ce20d84592766af35ef8dc02a8
ssdeep 12288:GsRUMGBcCI9zmSUpz9j6sUPDM6XGlnUCprR9ZzxcS3Mnwr6YaGdMT:GRTI9zm/Z9e7DMR9YyjdM
TLSH T159F42342D913D722E08FB17EC60E2F646D339C8DDC5994E605E6E6F9807B7D02D28A4B
TrID 45.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.3% (.EXE) OS/2 Executable (generic) (2029/13)
18.0% (.EXE) Generic Win/DOS Executable (2002/3)
18.0% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter KnownSpotter
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Stub.exe
Verdict:
Malicious activity
Analysis date:
2026-09-14 13:59:23 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Adding an access-denied ACE
Launching cmd.exe command interpreter
Creating a process with a hidden window
Searching for synchronization primitives
Launching a process
Using the Windows Management Instrumentation requests
Creating a file
Creating a file in the Program Files directory
Creating a file in the Program Files subdirectories
Modifying an executable file
Moving a file to the Program Files subdirectory
Changing a file
Modifies multiple files
Replacing files
Replacing executable files
Creating a window
Modifying a system file
Moving a system file
Blocking the Windows Defender launch
Deleting volume shadow copies
Preventing system recovery
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Creating a file in the mass storage device
Encrypting user's files
Infecting executable files
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm entropy filecoder krypt microsoft_visual_cc packed ransomware
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-30T00:57:00Z UTC
Last seen:
2026-09-26T22:07:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE Memory-Mapped (Dump)
Threat name:
Win64.Ransomware.WannaCry
Status:
Malicious
First seen:
2026-09-15 22:46:51 UTC
File Type:
PE+ (Exe)
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
GenericRansomware
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion evasion execution impact persistence ransomware spyware stealer trojan
Behaviour
Interacts with shadow copies
Modifies registry class
Opens file in notepad (likely ransom note)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
Drops file in Program Files directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Enumerates connected drives
Checks computer location settings
Deletes itself
Reads user/profile data of web browsers
Disables use of System Restore points
Deletes shadow copies
Modifies boot configuration data using bcdedit
Modifies Windows Defender Real-time Protection settings
Unpacked files
SH256 hash:
70b6b983b1d9e90206328dbdea8f044682e1be807ec6e9c71dcd0cd76f3dbe9c
MD5 hash:
162c454c5a8ec5d998119b606d234000
SHA1 hash:
4f396620696537410eaf6e9438c3b07ab0099d37
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments