MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1
SHA3-384 hash: 600543cc7daf5578f82d77b7c188c48d54b5cfcd81a0157f794f3246fff99eb5e4c844e6e96fb7b1906292aaabd0e1d6
SHA1 hash: 953f73b8bd7d432827eab7f00b4a0335b9485315
MD5 hash: caacf1183fa10d1feca3705e61561eab
humanhash: montana-monkey-fourteen-winner
File name:silkebin.exe
Download: download sample
File size:81'716'160 bytes
First seen:2026-08-01 21:22:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 58296c9611b6534d4a5f81a14eedb050
ssdeep 786432:uIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII8:V
TLSH T1D0085A0F3DE91613C99E16360C3D27FA03BDE54295A9A3935221EB6CE8DE1F978241D3
TrID 25.8% (.EXE) Win64 Executable (generic) (6522/11/2)
22.0% (.FON) Windows Font (5545/9/1)
19.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.1% (.ICL) Windows Icons Library (generic) (2059/9)
8.0% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Anonymous
Tags:clipjacker exe Rust signed

Code Signing Certificate

Organisation:{2560B96E-8A14-493C-A129-6C3B4ACF0BE1}
Issuer:{2560B96E-8A14-493C-A129-6C3B4ACF0BE1}
Algorithm:sha1WithRSAEncryption
Valid from:2025-04-17T23:51:28Z
Valid to:2026-04-18T05:51:28Z
Serial number: 44425f8b1a0c62a648437a79fdebbee1
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: bc71c80fb92ab1e38a2e5270f55b26e1913ca22acf7771694a801b667159ed9a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Creating a window
Creating a file in the %AppData% subdirectories
Creating a file
Creating a process from a recently created file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto expired-cert keylogger reconnaissance rust signed
Verdict:
Malicious
File Type:
exe x64
First seen:
2025-11-15T05:21:00Z UTC
Last seen:
2026-07-12T03:38:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win64.Infostealer.ClipBanker
Status:
Malicious
First seen:
2025-10-31 09:30:10 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates connected drives
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments