🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71feecc58bf7d3a7a658c40fc67f448522108714de20bd8387ee09d785051489. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkCloud


Vendor detections: 19


Intelligence 19 IOCs YARA 4 File information Comments

SHA256 hash: 71feecc58bf7d3a7a658c40fc67f448522108714de20bd8387ee09d785051489
SHA3-384 hash: b6c4214e7498d55c41941cdc1e5e8620d5d611af5f5940497df9e5c1943e9b3eece3794f378d375973e4bef24706abec
SHA1 hash: 0a9cacd07365e8da82532df9378bd6d9dc92cb5d
MD5 hash: 03de1ba3e8d9f38cfd59d746df680e73
humanhash: pennsylvania-fourteen-idaho-oxygen
File name:ziraat Bankasi Swift Mesaji,pdf.z.scr
Download: download sample
Signature DarkCloud
File size:1'322'496 bytes
First seen:2026-04-06 08:53:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'504 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 24576:+8fd4ah4WRoGLXsxkKPvOF8snkjFaXFyEoybnTOUJQMxySFHKVikYSJJSHw:+8fdIWRZzULPvm8sn2chnTOkQ/9i9qUw
Threatray 999 similar samples on MalwareBazaar
TLSH T10A5502452259DE02C8A35FF41D70E3750BF46D95A522D3138EFA3EEBBA39B01A904387
TrID 25.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
25.3% (.EXE) Win64 Executable (generic) (6522/11/2)
17.5% (.EXE) Win32 Executable (generic) (4504/4/1)
8.0% (.ICL) Windows Icons Library (generic) (2059/9)
7.8% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter threatcat_ch
Tags:DarkCloud exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
CH CH
Vendor Threat Intelligence
Gathering data
Malware family:
n/a
ID:
1
File name:
ziraat Bankasi Swift Mesaji,pdf.z.scr
Verdict:
Malicious activity
Analysis date:
2026-04-06 08:54:02 UTC
Tags:
auto-startup evasion stealer smtp amsi-bypass darkcloud upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
autorun micro small hype
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
DNS request
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Connection attempt
Sending an HTTP GET request
Creating a file in the %AppData% subdirectories
Reading critical registry keys
Stealing user critical data
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
darkcloud formbook masquerade obfuscated packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-04-06T05:25:00Z UTC
Last seen:
2026-04-07T23:45:00Z UTC
Hits:
~100
Detections:
Trojan-Spy.Agent.SMTP.C&C HEUR:Backdoor.MSIL.XWorm.gen PDM:Trojan.Win32.Generic Trojan.MSIL.Inject.sb Trojan.MSIL.Dnoper.sb Trojan.MSIL.Crypt.sb Trojan.MSIL.Agent.sb Trojan-PSW.Win32.Stelega.sb Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.DarkCloud.sb NetTool.PlainTextCredentials.SMTP.C&C HackTool.ReconScan.HTTP.ServerRequest
Result
Threat name:
DarkCloud
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
AI detected malicious Powershell script
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows shortcut file (LNK) contains suspicious command line arguments
Yara detected AntiVM3
Yara detected DarkCloud
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1893922 Sample: ziraat Bankasi Swift Mesaji... Startdate: 06/04/2026 Architecture: WINDOWS Score: 100 59 showip.net 2->59 71 Found malware configuration 2->71 73 Malicious sample detected (through community Yara rule) 2->73 75 Antivirus detection for dropped file 2->75 77 14 other signatures 2->77 10 ziraat Bankasi Swift Mesaji,pdf.z.scr.exe 8 2->10         started        14 powershell.exe 19 2->14         started        signatures3 process4 file5 49 C:\Users\user\AppData\...\cRDzJbhvHAoo.exe, PE32 10->49 dropped 51 C:\Users\...\cRDzJbhvHAoo.exe:Zone.Identifier, ASCII 10->51 dropped 53 C:\Users\user\AppData\...\wypafhcgykr.ps1, ASCII 10->53 dropped 55 ziraat Bankasi Swi...i,pdf.z.scr.exe.log, ASCII 10->55 dropped 79 Injects a PE file into a foreign processes 10->79 16 ziraat Bankasi Swift Mesaji,pdf.z.scr.exe 2 24 10->16         started        21 cRDzJbhvHAoo.exe 14->21         started        23 conhost.exe 1 14->23         started        signatures6 process7 dnsIp8 57 showip.net 162.55.60.2, 49719, 49726, 80 ACPCA United States 16->57 43 C:\Users\user\AppData\...\chrome.exe (copy), PE32 16->43 dropped 45 C:\Users\user\AppData\...\Project1.exe, PE32 16->45 dropped 61 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 16->61 63 Tries to steal Mail credentials (via file / registry access) 16->63 25 chrome.exe 2 16->25         started        28 taskkill.exe 1 16->28         started        65 Antivirus detection for dropped file 21->65 67 Multi AV Scanner detection for dropped file 21->67 69 Injects a PE file into a foreign processes 21->69 30 cRDzJbhvHAoo.exe 21->30         started        file9 signatures10 process11 file12 47 C:\Program Filesbehaviorgraphoogle\...behaviorgraphoogle-Chrome.exe, PE32+ 25->47 dropped 33 Google-Chrome.exe 1 1 25->33         started        35 conhost.exe 28->35         started        81 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 30->81 83 Tries to steal Mail credentials (via file / registry access) 30->83 85 Tries to harvest and steal browser information (history, passwords, etc) 30->85 37 taskkill.exe 30->37         started        signatures13 process14 process15 39 conhost.exe 33->39         started        41 conhost.exe 37->41         started       
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.30 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.PhantomStealer
Status:
Malicious
First seen:
2026-04-06 08:54:15 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
darkcloud
Score:
  10/10
Tags:
family:darkcloud defense_evasion discovery spyware stealer
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Checks computer location settings
Drops startup file
Executes dropped EXE
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
DarkCloud
Darkcloud family
Unpacked files
SH256 hash:
71feecc58bf7d3a7a658c40fc67f448522108714de20bd8387ee09d785051489
MD5 hash:
03de1ba3e8d9f38cfd59d746df680e73
SHA1 hash:
0a9cacd07365e8da82532df9378bd6d9dc92cb5d
SH256 hash:
b858cd95cdeb55059582789528f9be3a768ab55cbbaae6078f9f1ff7363dd40c
MD5 hash:
6a4cb750a7dbc473a9fc58286fb28ce7
SHA1 hash:
01135bb633ba2acbfd2da3cc654fa3775b552f58
SH256 hash:
2ea20d9a997bf40cd9876b9055651e93a9fe0f2e7f1e524020023ec7fdc92517
MD5 hash:
375f73650c730e550c20815b349edac6
SHA1 hash:
86c1cb0902c6e9189a4bea78f475c6f9241fb117
Detections:
darkcloudstealer INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_TelegramChatBot INDICATOR_SUSPICIOUS_EXE_CC_Regex MALWARE_Win_A310Logger MALWARE_Win_DarkCloud
SH256 hash:
4415032950c74e9f94ced219c758d14bca6837c01faf8cfe804ba68e77a66a38
MD5 hash:
ccb69b4d66438095a377dddd039f4f43
SHA1 hash:
88f4becef4b7a69ef156704b9632224a2c6f051c
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
3b75425895af4ae3186b36277553641e37ca1d620ae18d68e40d13351b54de6a
MD5 hash:
94d1531b52774dce52a89e33646d5b1d
SHA1 hash:
29bf887b025b97bd7a9e1e261852ba824234a625
Malware family:
DarkCloud
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkCloud

Executable exe 71feecc58bf7d3a7a658c40fc67f448522108714de20bd8387ee09d785051489

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments