MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81678485f2e5d8b395d310196c0086d7e495c4e0eb9d4e649b03eb6934360d53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Smoke Loader


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: 81678485f2e5d8b395d310196c0086d7e495c4e0eb9d4e649b03eb6934360d53
SHA3-384 hash: 9b6a2e1fd30e5c1a23ef1105c4e54afa951fa1bf6ead3e061cb7a4af8ab3ee769e8ee3e0544eee5c771643b77bfe56b1
SHA1 hash: 2793bfac63b19b11ffcd18b4519f10a5fb952512
MD5 hash: 045b9ae335dd71e561676906697846f2
humanhash: nine-king-arkansas-fish
File name:81678485f2e5d8b395d310196c0086d7e495c4e0eb9d4e649b03eb6934360d53
Download: download sample
Signature Smoke Loader
File size:8'015'872 bytes
First seen:2026-06-05 06:53:58 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a3a50dc87b7ed376f697a82dac2da087 (2 x Smoke Loader)
ssdeep 196608:2KDnfpAuaem5DE/Wxu2uaI1KbexsOOQx:2KjfpTSQ/WqTie
Threatray 4 similar samples on MalwareBazaar
TLSH T1A886D0B12A2E78E2F46E31F15148783D38BCFA744F9544A4A948E84B4DA56513E3FC2F
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon f0e8b23030b2e8f0 (2 x Smoke Loader, 1 x Stealc)
Reporter JAMESWT_WT
Tags:Click-Hijacking-TDS exe Smoke Loader

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-06-05 07:26:56 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Connection attempt to an infection source
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-02-18T10:43:00Z UTC
Last seen:
2026-06-05T05:37:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win64.Trojan.StealC
Status:
Malicious
First seen:
2026-02-19 02:46:03 UTC
File Type:
PE+ (Exe)
Extracted files:
18
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:remus_stealer stealer
Behaviour
Detects Remus stealer
Family: Remus
Unpacked files
SH256 hash:
81678485f2e5d8b395d310196c0086d7e495c4e0eb9d4e649b03eb6934360d53
MD5 hash:
045b9ae335dd71e561676906697846f2
SHA1 hash:
2793bfac63b19b11ffcd18b4519f10a5fb952512
Malware family:
RemusLogger
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments