MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c79568e853b1bd106eb3e6364fb3ff3ffb3d46d2eb3486debca04d424a82b76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Latrodectus


Vendor detections: 18


Intelligence 18 IOCs YARA 4 File information Comments

SHA256 hash: 8c79568e853b1bd106eb3e6364fb3ff3ffb3d46d2eb3486debca04d424a82b76
SHA3-384 hash: 68440e59d251550c6d537edf38ca2b6131b92e704f579e12ee1220e3f15d0e2516241a748c66338babc4a08d19fc1f45
SHA1 hash: a69c295a063de394d927913577d7683788522c94
MD5 hash: 698b030f6c6e50af0238e2b619629415
humanhash: happy-twenty-fourteen-cardinal
File name:UpdaterTag.dll
Download: download sample
Signature Latrodectus
File size:70'656 bytes
First seen:2025-09-07 23:03:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash db7aeb75528663639689f852fd366243 (22 x Latrodectus)
ssdeep 768:mzsvRTYS+PB8OjYH8ZI5OxLVlwKuDf+2guwI5qPNzZZ9eZ1JampX2zNjMBAU:mzcAyOjCoPzw2ju9Ud39eZamItMBA
Threatray 297 similar samples on MalwareBazaar
TLSH T17663724BDAA261E8ECB9D274C2A27127F8707C5C5438BB169F518E235F61B30F52C784
Magika pebin
Reporter AntiSkidding
Tags:exe Latrodectus

Intelligence


File Origin
# of uploads :
1
# of downloads :
334
Origin country :
GB GB
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
UpdaterTag.dll
Verdict:
Malicious activity
Analysis date:
2025-09-07 22:25:41 UTC
Tags:
latrodectus

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
shellcode swrort virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 masquerade microsoft_visual_cc packed
Verdict:
Malicious
File Type:
dll x64
First seen:
2025-09-07T22:28:00Z UTC
Last seen:
2025-09-07T22:28:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Agent.xcacca Trojan.Win32.Agent.sb
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Lactrodectus
Status:
Malicious
First seen:
2025-09-07 22:25:42 UTC
File Type:
PE+ (Dll)
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Result
Malware family:
latrodectus
Score:
  10/10
Tags:
family:latrodectus
Malware Config
C2 Extraction:
https://gasrobariokley.com/work/
https://fadoklismokley.com/work/
Verdict:
Malicious
Tags:
Win.Keylogger.Lazy-10029334-0
YARA:
n/a
Unpacked files
SH256 hash:
8c79568e853b1bd106eb3e6364fb3ff3ffb3d46d2eb3486debca04d424a82b76
MD5 hash:
698b030f6c6e50af0238e2b619629415
SHA1 hash:
a69c295a063de394d927913577d7683788522c94
Detections:
win_latrodectus_auto win_latrodectus_g0 LatrodectusAES
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Latrodectus_AES
Author:enzok
Description:Latrodectus Payload
Rule name:Windows_Trojan_Latrodectus_841ff697
Author:Elastic Security
Rule name:win_latrodectus_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.latrodectus.
Rule name:win_unidentified_111_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.unidentified_111.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments