MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a7146972b76ffe7e2c22bcf91a5197e2efd0fe28a574bd5e6b04a5ba69fdcf9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Smoke Loader


Vendor detections: 15


Intelligence 15 IOCs YARA 16 File information Comments

SHA256 hash: 7a7146972b76ffe7e2c22bcf91a5197e2efd0fe28a574bd5e6b04a5ba69fdcf9
SHA3-384 hash: 5b3e95abb027817e78d4ec7ce38f6f5be47c50728eb5d6e08ae878f727276d4aeb22fe8a8f4217430c210f845e40af51
SHA1 hash: 11bda9027962b2ad3fdb39c237e824a6aef607a6
MD5 hash: 157c11069abe1d374dca749d464d48eb
humanhash: november-nebraska-louisiana-hawaii
File name:7a7146972b76ffe7e2c22bcf91a5197e2efd0fe28a574bd5e6b04a5ba69fdcf9
Download: download sample
Signature Smoke Loader
File size:2'787'664 bytes
First seen:2026-06-05 06:50:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7c75a83e117d2bdfb2814c53e840c172 (5 x SalatStealer, 4 x QuasarRAT, 2 x XWorm)
ssdeep 49152:L2hvRhHukNuXSHOqyNijHeK/OkFoSYgMZ4YYowSc2FtE4elY4EUNjQFOAlMxP7vz:MvONLqyNlKfIJZ4YFpW4e5/Nj42TvaY
Threatray 124 similar samples on MalwareBazaar
TLSH T173D51219D7F805F9E1B7D578CE924906EB36B84943A1E6CF03E469A51F372908E3DB02
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (904 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter JAMESWT_WT
Tags:Click-Hijacking-TDS exe Smoke Loader

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
x7a7146972b76ffe7e2c22bcf91a5197e2efd0fe28a574bd5e6b04a5ba69fdcf9.exe
Verdict:
Malicious activity
Analysis date:
2026-03-04 06:37:17 UTC
Tags:
m0yv phishing sinkhole golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
phishing expiro
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a file in the %AppData% directory
Modifying a system executable file
Launching a service
Launching a process
Loading a system driver
Creating a file in the system32 subdirectories
Using the Windows Management Instrumentation requests
Connection attempt to an infection source
Modifying an executable file
Modifying a system file
Creating a file in the Windows subdirectories
Creating a file
Enabling autorun for a service
Query of malicious DNS domain
Infecting executable files
Sending an HTTP POST request to an infection source
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-03-04T03:41:00Z UTC
Last seen:
2026-06-05T05:37:00Z UTC
Hits:
~10
Malware family:
Generic Malware
Verdict:
Malicious
Gathering data
Threat name:
Win64.Virus.Expiro
Status:
Malicious
First seen:
2026-03-04 05:23:07 UTC
File Type:
PE+ (Exe)
Extracted files:
88
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:remus_stealer botnet:b50ff7bc0136ba6a8d092a8353d68d04 discovery ransomware spyware stealer
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of SetThreadContext
Checks installed software on the system
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Detects Remus stealer
Family: Remus
Suspicious use of NtCreateUserProcessOtherParentProcess
Malware Config
C2 Extraction:
http://ropea.top:28313
http://coox.live:28313
http://baxe.pics:48261
Unpacked files
SH256 hash:
7a7146972b76ffe7e2c22bcf91a5197e2efd0fe28a574bd5e6b04a5ba69fdcf9
MD5 hash:
157c11069abe1d374dca749d464d48eb
SHA1 hash:
11bda9027962b2ad3fdb39c237e824a6aef607a6
SH256 hash:
b0dc7ec79f3e1aa5699c3ea5170a7505dfe0ac4265f0269944f24a4a366c7f0a
MD5 hash:
aff3acaf41886c365026ecae31b8896a
SHA1 hash:
f978ad0e45f77457c3afbe29a66662f35b868f5c
Detections:
triage_expiro_worm
SH256 hash:
cb963a4df619a55955e4d8e6d498b483cb5e29251b400a67ac56ac387136c258
MD5 hash:
5bc9cc7e7adc6f19c7cfea768f7fa58c
SHA1 hash:
39b5e1c90144dcc087bfec967f805acde767d03e
Detections:
triage_expiro_worm
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:Windows_Trojan_M0yv_92f66467
Author:Elastic Security
Rule name:win_m0yv_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.m0yv.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments