MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79e494bd5dd5ce39998eb5831e37494510010534dfd959caaab226ae9f187c21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BlankGrabber


Vendor detections: 13


Intelligence 13 IOCs YARA 6 File information Comments

SHA256 hash: 79e494bd5dd5ce39998eb5831e37494510010534dfd959caaab226ae9f187c21
SHA3-384 hash: 07d89955caecfd8c80c2392f6fffd758103b70a782ca78bb8ff875e2249aec9914c473fb772568e13d29536b035bec1a
SHA1 hash: fbb6bae89d77eee6976c981a6de7cf50f3bba348
MD5 hash: 477218afb7eb3d24a13dd5cb8effa3ce
humanhash: snake-alpha-quebec-florida
File name:hackar.exe
Download: download sample
Signature BlankGrabber
File size:35'651'584 bytes
First seen:2026-06-14 11:22:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash cf72283be50852e418ce6bbb6b645835 (1 x BlankGrabber)
ssdeep 196608:wsFMPwpTNeN/FJMIDJf0gsAGKZpRp6qSWGfk:wz8q/Fqyf0gsqvp6/q
TLSH T1F97733B023A844E1E9F7463D8497C80AD6F4BC051B64EDCB136096292F277D84E7F7A6
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon ede4e0e0e0e4e0d8 (1 x BlankGrabber)
Reporter burger
Tags:BlankGrabber exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
BlankGrabber PyInstaller
Details
Malware family:
n/a
ID:
1
File name:
hackar.exe
Verdict:
No threats detected
Analysis date:
2026-06-14 11:21:47 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
shell virus sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Connection attempt
Creating a window
Сreating synchronization primitives
Running batch commands
Creating a process with a hidden window
DNS request
Launching a process
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
Loading a suspicious library
Enabling the 'hidden' option for analyzed file
Adding an exclusion to Microsoft Defender
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug expand installer-heuristic lolbin microsoft_visual_cc overlay packed reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-06-14T08:25:00Z UTC
Last seen:
2026-06-15T05:39:00Z UTC
Hits:
~100
Detections:
Trojan-Spy.Win32.Agent.dffz Trojan-PSW.Python.Blank.sb HEUR:Trojan-PSW.Python.Blank.gen Trojan-PSW.MSIL.Stealer.sb Trojan.Python.Agent.gen PDM:Trojan.Win32.Generic Trojan.Script.Poweliks.sb Trojan-PSW.Win32.Greedy.sb Trojan-PSW.Win32.Disco.sb Trojan.Win64.Agent.sb Trojan.Win32.Poweliks.a Trojan.Win32.Dizemp.sb Trojan.Win32.Agent.sb Trojan-PSW.Win64.Stealer.sb Trojan-PSW.Win64.Pyborg.sb
Result
Threat name:
Blank Grabber
Detection:
malicious
Classification:
rans.troj.adwa.spyw.expl.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Check if machine is in data center or colocation facility
Encrypted powershell cmdline option found
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found pyInstaller with non standard icon
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Modifies existing user documents (likely ransomware behavior)
Modifies the hosts file
Modifies Windows Defender protection settings
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Removes signatures from Windows Defender
Sigma detected: Capture Wi-Fi password
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Rar Usage with Password and Compression Level
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Sigma detected: Suspicious Startup Folder Persistence
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Crypto Currency Wallets
Uses attrib.exe to hide files
Uses cmd line tools excessively to alter registry or file data
Uses netsh to modify the Windows network and firewall settings
Uses WMIC command to query system information (often done to detect virtual machines)
Writes or reads registry keys via WMI
Yara detected Blank Grabber
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1927722 Sample: hackar.exe Startdate: 14/06/2026 Architecture: WINDOWS Score: 100 72 discord.com/api/webhooks/1515452490945134683/hrrc1h625du3ldtacsbvxsxubljulqbqrsybfs9exjftujc-lj_x_zm6ikt-oldlly5z unknown unknown 2->72 74 ip-api.com 2->74 76 2 other IPs or domains 2->76 84 Found malware configuration 2->84 86 Sigma detected: Capture Wi-Fi password 2->86 88 Multi AV Scanner detection for submitted file 2->88 90 12 other signatures 2->90 11 hackar.exe 62 2->11         started        15 svchost.exe 2->15         started        signatures3 process4 dnsIp5 64 C:\Users\user\AppData\Local\Temp\...\rar.exe, PE32+ 11->64 dropped 66 C:\Users\user\AppData\Local\...\rarreg.key, ASCII 11->66 dropped 68 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 11->68 dropped 70 56 other files (none is malicious) 11->70 dropped 118 Modifies Windows Defender protection settings 11->118 120 Adds a directory exclusion to Windows Defender 11->120 122 Tries to harvest and steal WLAN passwords 11->122 124 4 other signatures 11->124 18 hackar.exe 1 87 11->18         started        82 127.0.0.1 unknown unknown 15->82 file6 signatures7 process8 dnsIp9 78 ip-api.com 208.95.112.1, 49689, 49697, 80 TUT-AS-TotalUptimeTechnologiesLLCUS United States 18->78 80 discord.com 162.159.136.232, 443, 49698 CLOUDFLARENET-CloudflareIncUS Canada 18->80 92 Found many strings related to Crypto-Wallets (likely being stolen) 18->92 94 Tries to harvest and steal browser information (history, passwords, etc) 18->94 96 Modifies Windows Defender protection settings 18->96 98 7 other signatures 18->98 22 cmd.exe 1 18->22         started        25 cmd.exe 1 18->25         started        27 cmd.exe 1 18->27         started        29 33 other processes 18->29 signatures10 process11 signatures12 100 Suspicious powershell command line found 22->100 102 Uses cmd line tools excessively to alter registry or file data 22->102 104 Encrypted powershell cmdline option found 22->104 116 3 other signatures 22->116 31 powershell.exe 23 22->31         started        34 conhost.exe 22->34         started        106 Modifies Windows Defender protection settings 25->106 108 Removes signatures from Windows Defender 25->108 36 powershell.exe 25->36         started        46 2 other processes 25->46 110 Uses WMIC command to query system information (often done to detect virtual machines) 27->110 38 WMIC.exe 27->38         started        40 conhost.exe 27->40         started        112 Adds a directory exclusion to Windows Defender 29->112 114 Tries to harvest and steal WLAN passwords 29->114 42 getmac.exe 29->42         started        44 reg.exe 29->44         started        48 61 other processes 29->48 process13 file14 126 Loading BitLocker PowerShell Module 31->126 128 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 38->128 130 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 42->130 132 Writes or reads registry keys via WMI 42->132 58 C:\Users\user\AppData\...\ye3u45yn.cmdline, Unicode 48->58 dropped 60 C:\Users\user\AppData\Local\Temp\KrFB8.zip, RAR 48->60 dropped 51 csc.exe 48->51         started        54 Conhost.exe 48->54         started        signatures15 process16 file17 62 C:\Users\user\AppData\Local\...\ye3u45yn.dll, PE32 51->62 dropped 56 cvtres.exe 51->56         started        process18
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-14 11:21:32 UTC
File Type:
PE+ (Exe)
Extracted files:
8
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
blankgrabber
Score:
  10/10
Tags:
family:blankgrabber defense_evasion discovery execution stealer upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates processes with tasklist
UPX packed file
Looks up external IP address via web service
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Disables one or more Microsoft Defender components
Malware family:
BlankGrabber
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments