🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 944be60b0fbcbf625b47a4ea8064100124d3c0430855da6ec051cd3d494d964b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 944be60b0fbcbf625b47a4ea8064100124d3c0430855da6ec051cd3d494d964b
SHA3-384 hash: 491bf42e6f934d327b166e995ef5e4d461c3273bf6d7b754da81f6fc4f1e642dd9a026363161082ebeb41aaf5679a5ab
SHA1 hash: 3970148591dc727828eb1c459496a6e0f68dd5fd
MD5 hash: 79ddb58bd757774607b007a09ba1b664
humanhash: helium-oregon-nitrogen-red
File name:Изделие 170 габаритный чертеж.PDF.bin
Download: download sample
File size:885'872 bytes
First seen:2026-01-15 05:10:58 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9dda1a1d1f8a1d13ae0297b47046b26e (65 x Formbook, 50 x GuLoader, 28 x RemcosRAT)
ssdeep 24576:cPdu/mvtlSrSC31UPo0Fi0XjFlP+C7/nykVQ:EuMU/TFWjn2I+
TLSH T1091523415EA48927CE1A8D721CBC54B0AEF645BE43502F5D07189ABCFC24B7BFC6A613
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon ecd4d4d4d4f4d4d4
Reporter KodaDr
Tags:cobalt exe remcos signed

Code Signing Certificate

Organisation:rkn.gov.ru
Issuer:rkn.gov.ru
Algorithm:sha256WithRSAEncryption
Valid from:2025-07-10T00:00:00Z
Valid to:2027-07-10T00:00:00Z
Serial number: 64f852efe6c4ad23
Thumbprint Algorithm:SHA256
Thumbprint: b8b3763a22c33a2d691caa87aa7e885a277adea0e3ec9c197c3764e7a8b96ba3
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
248
Origin country :
RU RU
Vendor Threat Intelligence
Malware configuration found for:
NSIS
Details
NSIS
extracted archive contents
PEPacker
a UPX version number and an unpacked binary
Malware family:
n/a
ID:
1
File name:
Отчет по НИОКР 1427-18 (шифр АИСТ).PDF.exe
Verdict:
Malicious activity
Analysis date:
2026-01-12 11:45:27 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
autorun cobalt remcos
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole cobalt installer installer installer-heuristic masquerade microsoft_visual_cc nsis obfuscated overlay packed remcos signed soft-404 unsafe
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-01-12T06:16:00Z UTC
Last seen:
2026-01-16T01:50:00Z UTC
Hits:
~1000
Detections:
Trojan.PowerShell.Cobalt.sb VHO:Backdoor.Win32.Remcos.gen HEUR:Trojan.Win32.Cobalt.gen Trojan-Downloader.Agent.HTTP.C&C Trojan.Win32.Agent.sb PDM:Trojan.Win32.Generic HEUR:Trojan.Win32.Convagent.gen HEUR:Trojan.Win32.Agent.gen NetTool.PowerShellGet.HTTP.C&C NetTool.GitHubGetRepo.HTTP.C&C NetTool.PowerShellUA.HTTP.C&C
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Backdoor.Remcos
Status:
Suspicious
First seen:
2026-01-12 13:19:25 UTC
File Type:
PE (Exe)
Extracted files:
15
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery upx
Behaviour
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops startup file
Unpacked files
SH256 hash:
944be60b0fbcbf625b47a4ea8064100124d3c0430855da6ec051cd3d494d964b
MD5 hash:
79ddb58bd757774607b007a09ba1b664
SHA1 hash:
3970148591dc727828eb1c459496a6e0f68dd5fd
SH256 hash:
5a17d3c3d844c3ccd484b422789a8a5df9517ad888a93bb4bd2bff8b8956436d
MD5 hash:
fa81ea462bb76153897e3ee26319db2a
SHA1 hash:
ffe54fa36d4e8de7af595af457b2d7e5b03d9623
SH256 hash:
01e72332362345c415a7edcb366d6a1b52be9ac6e946fb9da49785c140ba1a4b
MD5 hash:
b4579bc396ace8cafd9e825ff63fe244
SHA1 hash:
32a87ed28a510e3b3c06a451d1f3d0ba9faf8d9c
SH256 hash:
1b16c41ae39b679384b06f1492b587b650716430ff9c2e079dca2ad1f62c952d
MD5 hash:
11fa744ebf6a17d7dd3c58dc2603046d
SHA1 hash:
d99de792fd08db53bb552cd28f0080137274f897
SH256 hash:
6ed33858b59ca6cb769db55c6a841288a1e08603409d5448867bc15eda4068ce
MD5 hash:
fa4b472320cb003b1c549e40e953195d
SHA1 hash:
dd2c2c578dc8c76bc77483414c7e6b7420c779f2
SH256 hash:
9111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706
MD5 hash:
4add245d4ba34b04f213409bfe504c07
SHA1 hash:
ef756d6581d70e87d58cc4982e3f4d18e0ea5b09
Malware family:
Defendnot
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments