MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7235824ba881093e6cf67bce58acc73b01f0e60378bb0050d62d4a68fcfd0c22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SWORDLDR


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 7235824ba881093e6cf67bce58acc73b01f0e60378bb0050d62d4a68fcfd0c22
SHA3-384 hash: 9c3ec077e9fc10793c8d8aa3654bdcfbba9bb7efb3344c9cc13aceb29c66bc2c1e4af0f33a0d33ff3e0b2422c40cb8e6
SHA1 hash: d91544262083918816470d03e26a39d9624ca992
MD5 hash: f5b44689804b2512596ba5ad25424187
humanhash: mockingbird-coffee-may-winner
File name:oci.dll
Download: download sample
Signature SWORDLDR
File size:150'016 bytes
First seen:2026-01-08 16:11:34 UTC
Last seen:2026-01-08 18:26:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash dceb10bcc797e2a2f948d5ee9049c3b2 (1 x SWORDLDR)
ssdeep 3072:s/JzHTkscMe1Kfm9J8D5ilR8OhloQmYxEkrJfsd:EHTncJ1KfclOOh2qvts
TLSH T1C4E3C68031C1C4F8E08FE53277776DE6E96294A7826A516E27C25E8E574B46C0CF7AC3
TrID 38.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
15.6% (.ICL) Windows Icons Library (generic) (2059/9)
15.4% (.EXE) OS/2 Executable (generic) (2029/13)
15.2% (.EXE) Generic Win/DOS Executable (2002/3)
15.2% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter BlinkzSec
Tags:exe SWORDLDR

Intelligence


File Origin
# of uploads :
3
# of downloads :
117
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
oci.dll
Verdict:
No threats detected
Analysis date:
2026-01-08 16:13:15 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
81.4%
Tags:
shellcode virus
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade microsoft_visual_cc
Verdict:
Clean
File Type:
dll x64
First seen:
2026-01-05T04:49:00Z UTC
Last seen:
2026-01-08T14:25:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-01-05 08:42:13 UTC
File Type:
PE+ (Dll)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
swordldr
Similar samples:
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
7235824ba881093e6cf67bce58acc73b01f0e60378bb0050d62d4a68fcfd0c22
MD5 hash:
f5b44689804b2512596ba5ad25424187
SHA1 hash:
d91544262083918816470d03e26a39d9624ca992
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SWORDLDR

Executable exe 7235824ba881093e6cf67bce58acc73b01f0e60378bb0050d62d4a68fcfd0c22

(this sample)

  
Delivery method
Distributed via web download

Comments