MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80cd87cbf731d14baa0698a22a0ebf8db7b305a740d0015d985e94b6b197a2f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CNBackdoor


Vendor detections: 6


Intelligence 6 IOCs YARA 12 File information Comments

SHA256 hash: 80cd87cbf731d14baa0698a22a0ebf8db7b305a740d0015d985e94b6b197a2f3
SHA3-384 hash: 23c0992014bd3168ef2c0bc56fb9d39ba73f8ac641d2993c5490632c569fa1e1f55abda35a80a74e0eae2853153281a6
SHA1 hash: 155ac54f910dca9a40165289b79410074c401380
MD5 hash: 5cae55328112416dd21369d80194f8b0
humanhash: high-magnesium-jig-moon
File name:Installer.iso
Download: download sample
Signature CNBackdoor
File size:15'337'472 bytes
First seen:2026-08-15 00:28:59 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 393216:gI0EHldZw7OgWtsKvdJhYZDr7fQCx7VR3QSMMaVTH0D2:gwSOptsKvdUz1xJxjMMEH
TLSH T1F2F633A64256D15ADDB0503A6BD0E9B99A11BB444C2D030D2FE73ABDF3E52B2BFC105C
TrID 88.7% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Magika iso
Reporter aachum
Tags:CNBackdoor iso


Avatar
iamaachum
https://dl89sfilesbase.top/downloads/K8fRy6W/Packed

CNBackdoor C2:
https://tommysbakescodes.ws/mnlinmwv/insris.php
https://tabbysbakescodes.ws/mnlinmwv/insris.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
ES ES
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:LauncherV33281.exe
File size:15'284'224 bytes
SHA256 hash: f4a8e4307944c6decec264820f699e4e4adee02fc71da530ad862dee959528cb
MD5 hash: fe1df8e405bcd3672f3cafbb667831c0
MIME type:application/x-dosexec
Signature CNBackdoor
File name:ReadMe.txt
File size:762 bytes
SHA256 hash: ba885bffe7c128af7e66b5b0a7c954201dfc17ec79780bf1b450e3e3c5ff91e1
MD5 hash: 2eaf0d6712becf502d90f78b30e1d85e
MIME type:text/plain
Signature CNBackdoor
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated packed packed themidawinlicense
Verdict:
Malicious
File Type:
iso
First seen:
2026-08-14T22:57:00Z UTC
Last seen:
2026-08-14T23:20:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Executable ISO9660 Image PE (Portable Executable) PE File Layout
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:INDICATOR_EXE_Packed_Themida
Author:ditekSHen
Description:Detects executables packed with Themida
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:win32_dotnet_obfuscate
Author:Reedus0
Description:Rule for detecting .NET obfuscated malware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CNBackdoor

iso 80cd87cbf731d14baa0698a22a0ebf8db7b305a740d0015d985e94b6b197a2f3

(this sample)

  
Delivery method
Distributed via web download

Comments