🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9af4e139869f56b4d259c0f05fe9b4cb9e9dab6cd7c13de7fa01d56126acd6ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 7 File information Comments

SHA256 hash: 9af4e139869f56b4d259c0f05fe9b4cb9e9dab6cd7c13de7fa01d56126acd6ba
SHA3-384 hash: cdf91f78725a924923e999148a15193c9432500960031c0e393f75293f073c464dd88856eeeafc5e0e79ace4e429b4d0
SHA1 hash: 2a23542a65593afdb420f23931c264f911755b00
MD5 hash: 0010c09e584eeee0cf2231fc30a8c65e
humanhash: fourteen-king-arizona-oven
File name:9af4e139869f56b4d259c0f05fe9b4cb9e9dab6cd7c13de7fa01d56126acd6ba.exe
Download: download sample
File size:1'012'224 bytes
First seen:2026-10-02 10:27:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 8d85f1e898b519a4e6349947a5b44061
ssdeep 24576:/BJE7HK7kU0O9u6gxGvlzPIstAQqXO0K0:/c4kTNvxu8stAPe0K0
TLSH T19625E052BBF04EF9F14BCA799D45A205A73274065BD4A4FF02BD465ACEA22F00EF9143
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 4c3269cccc69324c (1 x CoinMiner)
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
217
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Suspicious activity
Analysis date:
2026-10-02 10:36:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Creating a window
Launching a service
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug microsoft_visual_cc
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Suspicious access to claude desktop data directory by non-Claude process
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1981225 Sample: 589a07qY7d.exe Startdate: 02/10/2026 Architecture: WINDOWS Score: 100 31 konradkertc6.website 2->31 39 Multi AV Scanner detection for submitted file 2->39 41 Joe Sandbox ML detected suspicious sample 2->41 8 explorer.exe 29 7 2->8 injected 12 589a07qY7d.exe 2->12         started        signatures3 process4 dnsIp5 33 konradkertc6.website 172.67.159.178, 443, 49714 CLOUDFLARENET-CloudflareIncUS Canada 8->33 43 System process connects to network (likely due to code injection or exploit) 8->43 45 Tries to steal Mail credentials (via file / registry access) 8->45 47 Found many strings related to Crypto-Wallets (likely being stolen) 8->47 55 4 other signatures 8->55 14 chrome.exe 6 8->14         started        49 Injects code into the Windows Explorer (explorer.exe) 12->49 51 Writes to foreign memory regions 12->51 53 Allocates memory in foreign processes 12->53 57 2 other signatures 12->57 signatures6 process7 dnsIp8 35 192.168.2.24 unknown unknown 14->35 37 192.168.2.6, 138, 443, 49709 unknown unknown 14->37 17 chrome.exe 14->17         started        21 chrome.exe 14->21         started        process9 dnsIp10 25 www.google.com 142.251.155.119, 443, 49718, 49723 GOOGLE-GoogleLLCUS United States 17->25 27 dl.google.com 142.251.215.46, 49753, 80 GOOGLE-GoogleLLCUS United States 17->27 29 4 other IPs or domains 17->29 23 Chrome Cache Entry: 182, PDP-11 17->23 dropped file11
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-02 10:28:19 UTC
File Type:
PE+ (Exe)
Extracted files:
5
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Enumerates connected drives
Unpacked files
SH256 hash:
9af4e139869f56b4d259c0f05fe9b4cb9e9dab6cd7c13de7fa01d56126acd6ba
MD5 hash:
0010c09e584eeee0cf2231fc30a8c65e
SHA1 hash:
2a23542a65593afdb420f23931c264f911755b00
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 9af4e139869f56b4d259c0f05fe9b4cb9e9dab6cd7c13de7fa01d56126acd6ba

(this sample)

  
Delivery method
Distributed via web download

Comments