MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7fdd6fde6ea2e3d40119544558b89ec7d1f295a2b00e2f1383cb728caae1af74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NodeStealer


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 7fdd6fde6ea2e3d40119544558b89ec7d1f295a2b00e2f1383cb728caae1af74
SHA3-384 hash: e37b333de178452bcbb08e9faaa0e8ed4b921e7d410c9bb256b42fa7da78ac0f8e8a47004fb6f4756649516c2baa32a3
SHA1 hash: 7459af2d0be84580a0c273f709d0f60f2c2eafa2
MD5 hash: d84608df8858012a0973ada6fcf8cc84
humanhash: uranus-pizza-music-chicken
File name:mpextms.exe
Download: download sample
Signature NodeStealer
File size:86'065'735 bytes
First seen:2026-07-17 09:27:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (589 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:RD+BaWatprfMFHjfem8aI32PYUBFyTAzA83iXNJpX0UN6OC5vk61wPlxyOui/8ai:p+ZCrfMFHC6QyFaAyXNJpEk3MvB1OyOA
TLSH T1261833A44C25C5A1DB3405729266B463AFB90F018AD71CD2418C3DBA37BCBBC696F5F2
TrID 27.0% (.EXE) Win64 Executable (generic) (6522/11/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.4% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter smica83
Tags:exe NodeStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
vmdetect autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 bash cmd crypto crypto expired-cert fingerprint hacktool installer installer invalid-signature lolbin microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-17T06:57:00Z UTC
Last seen:
2026-07-18T19:10:00Z UTC
Hits:
~10
Detections:
Trojan-PSW.Win32.Alien.th Trojan-Dropper.Win64.Agentb.sb HEUR:Trojan-PSW.Script.Disco.gen
Result
Threat name:
Node Stealer
Detection:
malicious
Classification:
troj.adwa.spyw.evad
Score:
68 / 100
Signature
Drops large PE files
Drops PE files to the startup folder
Sigma detected: PowerShell Get-Process LSASS
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Yara detected Node Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1944102 Sample: mpextms.exe Startdate: 17/07/2026 Architecture: WINDOWS Score: 68 50 www.spotify.com 2->50 52 www.myexternalip.com 2->52 54 3 other IPs or domains 2->54 62 Yara detected Node Stealer 2->62 64 Sigma detected: PowerShell Get-Process LSASS 2->64 9 mpextms.exe 405 2->9         started        signatures3 process4 file5 34 C:\Users\user\AppData\Local\...\Installer.exe, PE32+ 9->34 dropped 36 C:\Users\user\AppData\Local\...\nsis7z.dll, PE32 9->36 dropped 38 C:\Users\user\AppData\Local\...\System.dll, PE32 9->38 dropped 40 24 other files (none is malicious) 9->40 dropped 66 Drops large PE files 9->66 13 Installer.exe 21 9->13         started        signatures6 process7 dnsIp8 56 upload.gofile.io 160.202.167.55, 443, 49780 GSLNETWORKS-AS-APGSLNetworksPtyLTDAU United States 13->56 58 www.myexternalip.com 34.160.111.145, 443, 49777, 49779 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 13->58 60 2 other IPs or domains 13->60 42 C:\Users\user\AppData\Roaming\...\Updater.exe, PE32+ 13->42 dropped 44 C:\Users\user\AppData\...\cookies.sqlite-shm, data 13->44 dropped 46 C:\Users\user\AppData\Local\...\passwords.db, SQLite 13->46 dropped 48 4 other files (3 malicious) 13->48 dropped 68 Drops PE files to the startup folder 13->68 70 Tries to harvest and steal browser information (history, passwords, etc) 13->70 72 Drops large PE files 13->72 74 Unusual module load detection (module proxying) 13->74 18 cmd.exe 1 13->18         started        20 cmd.exe 1 13->20         started        22 Installer.exe 13->22         started        24 2 other processes 13->24 file9 signatures10 process11 process12 26 powershell.exe 11 18->26         started        28 conhost.exe 18->28         started        30 tasklist.exe 1 20->30         started        32 conhost.exe 20->32         started       
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution spyware stealer
Behaviour
Checks processor information in registry
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Enumerates processes with tasklist
Checks computer location settings
Drops startup file
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments