MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7299233fbd3065c48bd98488db507956a52b9a780388e14e2ffde4d388c94ffe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



OffLoader


Vendor detections: 12


Intelligence 12 IOCs YARA 4 File information Comments

SHA256 hash: 7299233fbd3065c48bd98488db507956a52b9a780388e14e2ffde4d388c94ffe
SHA3-384 hash: a4d3de83bc367745c8e8b91056826b6bb4063b964412760ef5746c4a3e38a96e091a98835e5042f367edde061686ca5e
SHA1 hash: 51ba86c6cfbf13440f127ff8d85aa9ba36aaa950
MD5 hash: 2fab826976aec3d3e8923b50eceb0571
humanhash: tennessee-wyoming-fix-beryllium
File name:2fab826976aec3d3e8923b50eceb0571.exe
Download: download sample
Signature OffLoader
File size:2'098'454 bytes
First seen:2026-02-27 16:36:58 UTC
Last seen:2026-02-27 17:42:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (4 x OffLoader, 3 x Gh0stRAT, 1 x XWorm)
ssdeep 49152:duI5hROs3WcUUMxuUO6QQNJ8cOxqDNrlHgVn:d5/F3OnuMNucySNrlw
TLSH T1CEA5C03FF28BA13EE06E1A367972A110553B7A61A4128C5296FCF88CCF255701D3E797
TrID 50.8% (.EXE) Inno Setup installer (107240/4/30)
20.4% (.EXE) InstallShield setup (43053/19/16)
19.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.0% (.EXE) Win64 Executable (generic) (6522/11/2)
2.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe OffLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
87
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
iToolab UnlockGo 7 10 0 Full Crack Android for PC Windows .exe
Verdict:
Malicious activity
Analysis date:
2026-02-24 06:08:22 UTC
Tags:
delphi inno installer adware innosetup

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
98.2%
Tags:
shellcode dropper delphi virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug embarcadero_delphi fingerprint infostealer inno installer installer installer-heuristic packed soft-404
Result
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Trojan.Cerbu
Status:
Malicious
First seen:
2026-02-24 10:27:50 UTC
File Type:
PE (Exe)
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Unpacked files
SH256 hash:
7299233fbd3065c48bd98488db507956a52b9a780388e14e2ffde4d388c94ffe
MD5 hash:
2fab826976aec3d3e8923b50eceb0571
SHA1 hash:
51ba86c6cfbf13440f127ff8d85aa9ba36aaa950
SH256 hash:
986ccadde251eb2db19d948b2fa781d4e8b74d70eaf2a712c1a24e7570f8fc1f
MD5 hash:
adf75ef90f58d2d414aa5eeff58fe5f1
SHA1 hash:
20b2f22d1ce915c2b2ac22fdae3fdf0b8f3b52ac
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments