MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 883febd02d7bd5e48415a019a2e09dd59f41eca0dd525cd98cf08f7d460b3ada. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 7


Intelligence 7 IOCs YARA 22 File information Comments

SHA256 hash: 883febd02d7bd5e48415a019a2e09dd59f41eca0dd525cd98cf08f7d460b3ada
SHA3-384 hash: ccda3bc8bc18ac8721c111af1e6babd9ea8783ef892c86c5ca45912cc38afac54c6ffb9dc90e938c5b3106fcc7fcb118
SHA1 hash: 921afdd6a0fcb3c3b30c97c4fe92e9d5cb6ce660
MD5 hash: 442867ed1d1e917999662c4c00d7e43b
humanhash: venus-carpet-neptune-cat
File name:package
Download: download sample
Signature KongTuke
File size:16'871'794 bytes
First seen:2026-07-24 19:08:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:SxFJtiuVvaJP6lJtF6oardIX2+nj1orLUWlmJw1fsFi1M:Sptiu8duJL6HrdEdJ+kc1M
TLSH T10D07336874668648F169827850D3DFD0ADC60E86C31A740A6C1F7C9F33DB926DFA21ED
Magika zip
Reporter monitorsg
Tags:Kongtuke zip


Avatar
monitorsg
hXXps://marshalh[.]icu/3qpr8347.js (ClickFucker) --> hXXps://marshalh[.]icu/api/v1/session (token) --> hXXps://marshalh[.]icu/api/v1/verify (gateway) --> hXXps://marshalh[.]icu/api/v1/status (clipboard) --> hXXps://hosthex9101[.]com/update/package (tar)

Intelligence


File Origin
# of uploads :
1
# of downloads :
123
Origin country :
US US
File Archive Information

This file archive contains 23 file(s), sorted by their relevance:

File name:xul.dll
File size:8'611'840 bytes
SHA256 hash: e2132030c24169e9e615d1dc9f9e2c88f1c3036fdda5e0e6de8a46fe20c64fd9
MD5 hash: e68230b76b25974350f96d0b21cc61d4
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.manifest
File size:240 bytes
SHA256 hash: 23680bbba9edbbfab98e27f9bd676b031da3b20adfe909ce86c9ecc1b8bb80d1
MD5 hash: 5d5e62ad6d1023592406fe3ea1f0ea75
MIME type:text/xml
Signature KongTuke
File name:vcruntime140_1.dll
File size:47'264 bytes
SHA256 hash: e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
MD5 hash: 03b43160d21c08de07a79d0a1c5ee81d
MIME type:application/x-dosexec
Signature KongTuke
File name:AccessibleMarshal.dll
File size:939'520 bytes
SHA256 hash: e3c2a5faab50507fcea29b83f5dbaa86a02fc77d990b58f58ea703504845d398
MD5 hash: 12625fe59f12f95d57805fe4ccca00af
MIME type:application/x-dosexec
Signature KongTuke
File name:gkcodecs.dll
File size:939'520 bytes
SHA256 hash: 66c2d8d07319ad7369d6de525164b38e22c184125adc8e19e06f53f199ae3f16
MD5 hash: 1e138d4913da7bd947d9c2e66eeb5ec9
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.dll
File size:850'944 bytes
SHA256 hash: 3b81d6a2c3307f8d591a686a7e24bc6d13c1f1ad11beda51e72b6b747757b0e3
MD5 hash: 6275eeb7282bd71f39f86ead3865127c
MIME type:application/x-dosexec
Signature KongTuke
File name:plugin-container.exe
File size:144'512 bytes
SHA256 hash: b2f2b9a3a712125a06b303344b7a0dc57f91ee6f1749c731ca2260931dbe24e9
MD5 hash: 65729157b053d4d373595f7a53126298
MIME type:application/x-dosexec
Signature KongTuke
File name:wmfclearkey.dll
File size:892'416 bytes
SHA256 hash: aee24a3cfcb602be6ebfe55a4e41d0ae77961ddfac971a8e7c63df8bda97ae7c
MD5 hash: 90fe13d6d26e65a7379b2dc50a973020
MIME type:application/x-dosexec
Signature KongTuke
File name:freebl3.dll
File size:939'520 bytes
SHA256 hash: 80d3a6290ea91d06846330732bdb0ad6342647de4424bcf1a777e37cc947022c
MD5 hash: 8dbac3b51de2c0e579576fb0bc541113
MIME type:application/x-dosexec
Signature KongTuke
File name:mozinference.dll
File size:939'520 bytes
SHA256 hash: d769fdbc7cbc9700dc0cfd9776adf76d36c91174c1a5dc832100b98c40df1a31
MD5 hash: 274a6efdc39e6ee8072c297cb0546cde
MIME type:application/x-dosexec
Signature KongTuke
File name:vcruntime140.dll
File size:123'472 bytes
SHA256 hash: 184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
MD5 hash: 0d35c5e99871b4f02c490b9fd9dace34
MIME type:application/x-dosexec
Signature KongTuke
File name:nss3.dll
File size:940'032 bytes
SHA256 hash: 53663fdf607dd70d8512150df9f11d9f3a41f107c791c8a5672096c556ab1e88
MD5 hash: 50af992bd6a16a67e67fad9e3eb799c1
MIME type:application/x-dosexec
Signature KongTuke
File name:libEGL.dll
File size:3'077'632 bytes
SHA256 hash: eddbb4dbfc25769eaf32ed75de10549e45cea334b9ce6d180e1d6e82cc2b8517
MD5 hash: 2b15ee1dc7bd3becea604701a6369118
MIME type:application/x-dosexec
Signature KongTuke
File name:libGLESv2.dll
File size:3'091'968 bytes
SHA256 hash: d6c07265cc9a4f46c4c6d56a2a08262e4f512709172845424ea75e2ff8768bd4
MD5 hash: a514f4b70eca893eee2a2e53fcb302a7
MIME type:application/x-dosexec
Signature KongTuke
File name:nssutil3.dll
File size:6'480'896 bytes
SHA256 hash: bc312c6a96a919d1831f07243ca7e00effb1916c3babd488709a85e1dac18b3b
MD5 hash: 1a6b4ae5b76ec7ac2a7a681a5ecedf34
MIME type:application/x-dosexec
Signature KongTuke
File name:notificationserver.dll
File size:837'632 bytes
SHA256 hash: 4219549e0597dd4a036d8537c6bfce7cb64d1421d73c92da696a81e698558cf8
MD5 hash: eba8f80cbfe21c5e1e9adced7a8f4cea
MIME type:application/x-dosexec
Signature KongTuke
File name:plugin-container.exe.local
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature KongTuke
File name:mozavcodec.dll
File size:1'102'336 bytes
SHA256 hash: 1b602361b0bd34ac87ad2bcedb1c1255ad42a0ee602baeefe7a9e528b4d8f9e2
MD5 hash: d96b34c8d66b73c3658c70ed46cec033
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavutil.dll
File size:3'076'608 bytes
SHA256 hash: 50834b09a95622de87440b98b2a9da9acf3a924f5cbc73c2dd3643d5a85324e2
MD5 hash: b9350ba8f9c2f9485a012c656e8c3d5e
MIME type:application/x-dosexec
Signature KongTuke
File name:msvcp140.dll
File size:553'552 bytes
SHA256 hash: def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
MD5 hash: 4e3fa9bd90ef020c14359639dc19312b
MIME type:application/x-dosexec
Signature KongTuke
File name:mozwer.dll
File size:939'520 bytes
SHA256 hash: f70e061b7ce8da64c13994ce0aaa822151c264b391e357caf2b953de905fba70
MD5 hash: 74bf7d2fd1dd3c4ac7bee0d9c5b19ea5
MIME type:application/x-dosexec
Signature KongTuke
File name:lgpllibs.dll
File size:940'032 bytes
SHA256 hash: 833586786d9e9256f2e106f7e8758e2e37e0521dc1b4445f68a3f1531ce07c3b
MD5 hash: c0b53f5c32e4fe3b87cb26c479926a92
MIME type:application/x-dosexec
Signature KongTuke
File name:softokn3.dll
File size:940'544 bytes
SHA256 hash: a25c2a1038ffcd8041b71a1c99ffcfe2186a6d2dd9e342fb3cb932dc0c9e14fe
MD5 hash: c254491ef76f6f9571c742643c04fe25
MIME type:application/x-dosexec
Signature KongTuke
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.Wacatac
Status:
Malicious
First seen:
2026-07-24 19:10:03 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MoleBoxv20
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

zip 883febd02d7bd5e48415a019a2e09dd59f41eca0dd525cd98cf08f7d460b3ada

(this sample)

  
Delivery method
Distributed via web download

Comments