MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 864b83647942f5dec0746fb5a40cdcc661bbbceea0b8cbe5df0beb9f30c30d0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 3 File information Comments

SHA256 hash: 864b83647942f5dec0746fb5a40cdcc661bbbceea0b8cbe5df0beb9f30c30d0f
SHA3-384 hash: c933a11089f5d3be393452dd4a86bb3ce1f596cb4f2df771694fcdf964f1c272f5edcfc4f5b02fa473cbb98d42aebf71
SHA1 hash: d1bb17261ec6f639362c9322fb6c82102b364c6f
MD5 hash: 42483f4f8487af89170eded647376519
humanhash: edward-tennis-sad-fruit
File name:Оплаченый счет.com
Download: download sample
File size:1'384'948 bytes
First seen:2026-07-22 09:42:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9dda1a1d1f8a1d13ae0297b47046b26e (65 x Formbook, 46 x GuLoader, 28 x RemcosRAT)
ssdeep 24576:kadGJsuhKFecp7MziuHgkCCpRrjVLJ5EVyk8wuUhgj7nPljs7JbSTRo3rZ:jGJ3KFey6iuHgkCCrdFJ3rlbo9
TLSH T1615523403F22C6A6C9335B72AC6F4A94E763EE5E9441538737947205A8B31B0C97FED2
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 71f0c898c8c8dc00 (2 x Formbook, 1 x Rhadamanthys, 1 x IcarusStealer)
Reporter KodaDr
Tags:exe RareWerewolf

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
RU RU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Оплаченый счет.bin
Verdict:
No threats detected
Analysis date:
2026-07-22 09:19:42 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
Launching a process
Creating a process from a recently created file
Creating a process with a hidden window
Connection attempt
Сreating synchronization primitives
Creating a window
Sending a custom TCP request
Changing a file
Launching a service
Searching for synchronization primitives
Delayed reading of the file
Running batch commands
Creating a file in the %AppData% subdirectories
Searching for the window
Loading a suspicious library
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 fingerprint installer installer masquerade microsoft_visual_cc nsis packed reconnaissance
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.ToolX
Status:
Malicious
First seen:
2026-07-22 09:43:36 UTC
File Type:
PE (Exe)
Extracted files:
7
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware discovery execution persistence spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Runs ping.exe
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Windows directory
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Unpacked files
SH256 hash:
864b83647942f5dec0746fb5a40cdcc661bbbceea0b8cbe5df0beb9f30c30d0f
MD5 hash:
42483f4f8487af89170eded647376519
SHA1 hash:
d1bb17261ec6f639362c9322fb6c82102b364c6f
SH256 hash:
993dff08f417b232b65317382ae07faf4414e6b2bfb63b6001688995856c8c15
MD5 hash:
66f51bda6a404fbc54c90098a9e9c854
SHA1 hash:
d84529c2126e7c878f6ac52f7c3c2636c3995dda
SH256 hash:
bb243113d236f823abd1839025190e763fe34c40da4949b77558995cc1a07625
MD5 hash:
29086d9247fdf40452563c11b3dca394
SHA1 hash:
33b264f85caa86fcd81e5fd75e654a9a1a4c26c8
SH256 hash:
2cd3a2d4053954db1196e2526545c36dfc138c6de9b81f6264632f3132843c77
MD5 hash:
11092c1d3fbb449a60695c44f9f3d183
SHA1 hash:
b89d614755f2e943df4d510d87a7fc1a3bcf5a33
SH256 hash:
78dbe1fbbc7e5f51fa385be08bb679251e46b43be690fbc49c412d9d4f647a10
MD5 hash:
9542f4ac0caefa766bd67ba879ed2dd4
SHA1 hash:
ef93bf4c28fe70a90ae42e64a55900a6cb756eec
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:NSIS
Author:kevoreilly
Description:NSIS Integrity Check function
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments