🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a8a4a6b3fddb1f9610a62163495293df8f3625bb2b92ed2c43c3f100908fac0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 9a8a4a6b3fddb1f9610a62163495293df8f3625bb2b92ed2c43c3f100908fac0
SHA3-384 hash: 97c6ba790f44381ecb537e1ab833121b4d0d964b7c026d09e97842dd352d0d47d27c9d97d03e2ee352218b8bfb2eb115
SHA1 hash: 401c6660e8adcaf6cb791856da98a2d0ae8018cf
MD5 hash: 92c2c66f41e6194c1d26ad622d397d63
humanhash: nine-oxygen-sierra-vermont
File name:SecondRunner.exe
Download: download sample
Signature CoinMiner
File size:469'504 bytes
First seen:2026-09-27 12:52:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 033ee52b88ad8a2da2858497632d4fd4 (1 x CoinMiner)
ssdeep 12288:0+hGIC7L0bice4Ew59qHdExWvVisi12O1uM5V:BhGH0bQ4f9qHdaW9iBuMD
TLSH T165A45A03F5D041F7C04DC471C79A5633BA22FC4BC934BE6B6BA44E217E96BA0A769306
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter aachum
Tags:CoinMiner dropped-by-OffLoader exe


Avatar
iamaachum
https://fastsrunners.com/SecondRunner.exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-27 13:03:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm fingerprint
Result
Threat name:
Detection:
malicious
Classification:
phis.spyw.evad.mine
Score:
100 / 100
Signature
Antivirus detection for dropped file
Contains functionality to inject threads in other processes
Creates multiple autostart registry keys
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Found strings related to Crypto-Mining
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Sigma detected: Connection Initiated Via Certutil.EXE
Sigma detected: Legitimate Application Dropped Executable
Suspicious access to claude desktop data directory by non-Claude process
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses powercfg.exe to modify the power settings
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1978663 Sample: SecondRunner.exe Startdate: 27/09/2026 Architecture: WINDOWS Score: 100 112 cryptpeer.com 2->112 114 prl.kryptex.network 2->114 116 hotelcalifornia.club 2->116 136 Malicious sample detected (through community Yara rule) 2->136 138 Antivirus detection for dropped file 2->138 140 Multi AV Scanner detection for submitted file 2->140 142 5 other signatures 2->142 11 SecondRunner.exe 1 2->11         started        15 chrome140.exe 2->15         started        17 svchost.exe 1 1 2->17         started        19 8 other processes 2->19 signatures3 process4 dnsIp5 120 hotelcalifornia.club 104.21.3.87, 443, 49717, 49757 CLOUDFLARENET-CloudflareIncUS Canada 11->120 170 Tries to steal Instant Messenger accounts or passwords 11->170 172 Tries to steal Mail credentials (via file / registry access) 11->172 174 Found many strings related to Crypto-Wallets (likely being stolen) 11->174 176 5 other signatures 11->176 21 cmd.exe 1 11->21         started        23 cmd.exe 1 11->23         started        25 chrome.exe 6 11->25         started        28 gupdt.exe 15->28         started        30 gupw.exe 15->30         started        32 chrome140.exe 15->32         started        122 127.0.0.1 unknown unknown 17->122 signatures6 process7 dnsIp8 34 00614bd61.exe 21->34         started        38 certutil.exe 16 21->38         started        40 conhost.exe 21->40         started        42 00614b780.exe 23->42         started        44 certutil.exe 3 16 23->44         started        47 conhost.exe 23->47         started        118 192.168.2.6, 138, 443, 49467 unknown unknown 25->118 49 chrome.exe 25->49         started        51 chrome.exe 25->51         started        process9 dnsIp10 80 C:\ProgramDatabehaviorgraphoogle\...\googleupdater.exe, PE32+ 34->80 dropped 144 Antivirus detection for dropped file 34->144 146 Found stalling execution ending in API Sleep call 34->146 53 googleupdater.exe 34->53         started        82 C:\Users\user\AppData\Local\...\00614bd61.exe, PE32+ 38->82 dropped 84 C:\Users\...\0228456B33EEA3C1E749BC644A05CAE4, PE32+ 38->84 dropped 148 System process connects to network (likely due to code injection or exploit) 38->148 86 C:\Users\user\AppData\Local\...\gupw.exe, PE32+ 42->86 dropped 88 C:\Users\user\AppData\Local\...\gupdt.exe, PE32+ 42->88 dropped 96 2 other malicious files 42->96 dropped 150 Creates multiple autostart registry keys 42->150 152 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 42->152 154 Uses powercfg.exe to modify the power settings 42->154 57 00614b780.exe 42->57         started        59 gupdt.exe 42->59         started        61 powercfg.exe 42->61         started        63 2 other processes 42->63 124 cryptpeer.com 188.165.53.185, 443, 49758, 49759 OVHFR France 44->124 90 C:\Users\user\AppData\Local\...\00614b780.exe, PE32+ 44->90 dropped 92 C:\Users\...\2D84AD175EDF95992FFB5B8DE282E446, PE32+ 44->92 dropped 156 Queries DNS domain through GetComputerNameExW (potential sandbox evasion) 44->156 126 www.google.com 142.251.151.119, 443, 49720, 49721 GOOGLE-GoogleLLCUS United States 49->126 128 ogads-pa.clients6.google.com 142.251.45.202, 443, 49740, 49741 GOOGLE-GoogleLLCUS United States 49->128 130 3 other IPs or domains 49->130 94 Chrome Cache Entry: 149, PDP-11 49->94 dropped file11 signatures12 process13 file14 98 C:\ProgramDatabehaviorgraphoogle\...\nvidia-smi.exe, PE32+ 53->98 dropped 100 C:\ProgramDatabehaviorgraphoogle\Update\...\guanchor.dll, PE32+ 53->100 dropped 102 C:\ProgramData\...\crashpad_handler.exe, PE32+ 53->102 dropped 110 2 other malicious files 53->110 dropped 158 Antivirus detection for dropped file 53->158 160 Found stalling execution ending in API Sleep call 53->160 162 Creates multiple autostart registry keys 53->162 164 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 53->164 65 chrome.exe 53->65         started        68 crashpad_handler.exe 53->68         started        104 C:\ProgramDatabehaviorgraphoogle\...\googleanc.dll, PE32+ 57->104 dropped 106 C:\ProgramDatabehaviorgraphoogle\Chrome\...\google.exe, PE32+ 57->106 dropped 108 C:\ProgramDatabehaviorgraphoogle\Chrome\...\google.dll, PE32+ 57->108 dropped 166 Found strings related to Crypto-Mining 59->166 168 Unusual module load detection (module proxying) 59->168 70 conhost.exe 61->70         started        72 conhost.exe 63->72         started        signatures15 process16 signatures17 132 Found direct / indirect Syscall (likely to bypass EDR) 65->132 74 nvidia-smi.exe 65->74         started        76 nvidia-smi.exe 65->76         started        134 Contains functionality to inject threads in other processes 68->134 78 conhost.exe 68->78         started        process18
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
System Time Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks installed software on the system
Power Settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Downloads MZ/PE file
Unpacked files
SH256 hash:
9a8a4a6b3fddb1f9610a62163495293df8f3625bb2b92ed2c43c3f100908fac0
MD5 hash:
92c2c66f41e6194c1d26ad622d397d63
SHA1 hash:
401c6660e8adcaf6cb791856da98a2d0ae8018cf
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:TeslaCryptPackedMalware
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

Executable exe 9a8a4a6b3fddb1f9610a62163495293df8f3625bb2b92ed2c43c3f100908fac0

(this sample)

  
Delivery method
Distributed via web download

Comments