MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 888dba9b6af3eefee1af6835639b59022aa5ccf487cbdf0965887ca27f7c0478. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 888dba9b6af3eefee1af6835639b59022aa5ccf487cbdf0965887ca27f7c0478
SHA3-384 hash: bda5b326b683f9d8bfcfa116296f736b10e2fb3a8c90815001ed3857c4a5192733e81c05d25d0042cf246d24fafca4b0
SHA1 hash: 4d3b600fd76d9905269e1e96bf2a42ed7a1d106f
MD5 hash: dd3024193ef3e05ec51106966544fc42
humanhash: pasta-pizza-crazy-four
File name:mrxsmbmg.sys
Download: download sample
File size:14'976 bytes
First seen:2026-04-18 18:28:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0986c134ccc3041a3665a381bbdf8c83
ssdeep 192:6MCepUCEPUoRRwExvUrJFwbQizVoYZqXoGePV/k3K5/kK4W+FWAsL:ilRUoR7kw0pXAl5cK4W+FWA
TLSH T1EA623B42E95D8562D9F204F15A1E6A35BAFFD16007328EC397400B9B6E75EE0B83834F
TrID 38.1% (.EXE) Win64 Executable (generic) (6522/11/2)
26.3% (.EXE) Win32 Executable (generic) (4504/4/1)
11.8% (.EXE) OS/2 Executable (generic) (2029/13)
11.7% (.EXE) Generic Win/DOS Executable (2002/3)
11.7% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter smica83
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
96.5%
Tags:
equationdrug virus
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug equationdrug masquerade microsoft_visual_cc unsafe
Verdict:
Malicious
File Type:
sys x32
First seen:
2017-11-08T13:08:00Z UTC
Last seen:
2026-04-20T11:53:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Win32.EquationDrug.gen
Malware family:
UtilityBurst
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Gathering data
Verdict:
Malicious
Threat:
Trojan.Win32.EquationDrug
Threat name:
Win32.Trojan.EquationDrug
Status:
Suspicious
First seen:
2021-07-23 20:59:25 UTC
File Type:
PE (Sys)
AV detection:
22 of 36 (61.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
888dba9b6af3eefee1af6835639b59022aa5ccf487cbdf0965887ca27f7c0478
MD5 hash:
dd3024193ef3e05ec51106966544fc42
SHA1 hash:
4d3b600fd76d9905269e1e96bf2a42ed7a1d106f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments