MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 875dd7c1ef9a47fac8d3f50c945faf3afdea6e01d2d5c00f671110f62d97ebc1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 875dd7c1ef9a47fac8d3f50c945faf3afdea6e01d2d5c00f671110f62d97ebc1
SHA3-384 hash: 5d7104ee6581b0afd57fe9315871171d58120099faf9d1fd97875b12e344ec9d038d3f60c93895ba3256de57a64c082b
SHA1 hash: 359af93f963931fd7ee3f87a224f79f438551db9
MD5 hash: e0e8880b691b81812ec0f17a4f9d363b
humanhash: alpha-romeo-pizza-ack
File name:libcurl.dll
Download: download sample
File size:4'448'944 bytes
First seen:2026-07-18 17:09:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d9cdd14f1e51bf231e8fd705275c2c8a
ssdeep 24576:zsSNeB0IJIVX8QS1LkV7XbiiJynl6iLswXFZ2Huy:DNgDIVMkV7XbiiAl625Z2HN
TLSH T162264B14A105CD2FCB133ABDF816AADD7B5458A2CB02C22F12B48ED769E73D1644EB47
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 449271f0f0709244
Reporter kejult
Tags:dll exe signed trojan Yogi

Code Signing Certificate

Organisation:Battery Monitor
Issuer:Battery Monitor
Algorithm:sha256WithRSAEncryption
Valid from:2026-07-11T12:17:26Z
Valid to:2027-07-11T12:27:26Z
Serial number: 539d57f1d60d4fa94c6585d323da1e99
Thumbprint Algorithm:SHA256
Thumbprint: e149e8568dcf8dd3c795c100f6fcab19d0e11e7ec3f4c5e3815770c00f275341
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
201
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Quantum V4.zip
Verdict:
Suspicious activity
Analysis date:
2026-07-18 17:06:14 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc virus
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching a service
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug masquerade overlay packed signed
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-07-18T06:00:00Z UTC
Last seen:
2026-07-19T22:12:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Yogi
Status:
Malicious
First seen:
2026-07-18 10:43:52 UTC
File Type:
PE+ (Dll)
Extracted files:
6
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
875dd7c1ef9a47fac8d3f50c945faf3afdea6e01d2d5c00f671110f62d97ebc1
MD5 hash:
e0e8880b691b81812ec0f17a4f9d363b
SHA1 hash:
359af93f963931fd7ee3f87a224f79f438551db9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 875dd7c1ef9a47fac8d3f50c945faf3afdea6e01d2d5c00f671110f62d97ebc1

(this sample)

  
Delivery method
Distributed via web download

Comments