MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87ede06f4eefe1e961feeed2d3d856bd7b1ff9746b78179b9ae06b870d5fe4e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 4 File information Comments

SHA256 hash: 87ede06f4eefe1e961feeed2d3d856bd7b1ff9746b78179b9ae06b870d5fe4e4
SHA3-384 hash: 8c4f83ae3e9302f9bee01b2b2e0edd86bb4fd61a2fc01d0d148fc3950990afe6db75d983e866cf354866aa54709f1506
SHA1 hash: 58dd89e565a6b536fd31f0a983c6e69ee7961629
MD5 hash: 905b794bcf5189b89163f5633c293aa9
humanhash: four-fifteen-lamp-shade
File name:87ede06f4eefe1e961feeed2d3d856bd7b1ff9746b78179b9ae06b870d5fe4e4
Download: download sample
File size:193'024 bytes
First seen:2026-08-12 08:04:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 130b2dc32133536211cac2d13539245d
ssdeep 3072:7yrjIkNYVNAU3CDzv5HSoAJgsSkPNRKyD0t0Psr6cVCHd8foY46QZnV3cj0T87y:7KIb8U3Cnv5dA6FkPNky1PlcBohbH
TLSH T10C14291B339A32E9F4329139CA528543EB7D34751731877F2754422AAE636B4DE3BB20
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Anonymous
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
QuarantinedFile (4).zip
Verdict:
No threats detected
Analysis date:
2026-05-09 00:12:27 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Setting a keyboard event handler
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm keylogger keylogger microsoft_visual_cc mikey
Verdict:
Unknown
File Type:
exe x64
First seen:
2025-08-27T02:58:00Z UTC
Last seen:
2026-05-17T04:48:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-02 10:18:42 UTC
File Type:
PE+ (Exe)
AV detection:
22 of 36 (61.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
87ede06f4eefe1e961feeed2d3d856bd7b1ff9746b78179b9ae06b870d5fe4e4
MD5 hash:
905b794bcf5189b89163f5633c293aa9
SHA1 hash:
58dd89e565a6b536fd31f0a983c6e69ee7961629
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments