MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b30f3c425c9eb4d4bf7d6bca07b82f5f63fbcc92a43e0885b2e7613d76d7a1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SolarisLoader


Vendor detections: 12


Intelligence 12 IOCs YARA 7 File information Comments

SHA256 hash: 9b30f3c425c9eb4d4bf7d6bca07b82f5f63fbcc92a43e0885b2e7613d76d7a1d
SHA3-384 hash: 6e01d5f65b1c9a12724dd929caececda480f9fb8b4d6c803adaac2a9167aa72df0a05b7ccb425d0a37b6e2703834bfa5
SHA1 hash: dfcd9d67757f58cfd53719718239dd00bb1e39e2
MD5 hash: 0879e5569c1331665eabd5ab96b22c3d
humanhash: summer-lion-rugby-sodium
File name:0879e5569c1331665eabd5ab96b22c3d.exe
Download: download sample
Signature SolarisLoader
File size:40'960 bytes
First seen:2026-06-23 10:29:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9d6b7a90e30c979aada0c2c88281d1b8 (3 x SolarisLoader, 1 x Stealc)
ssdeep 768:ZvBc4FsYxddOnewn8yD5+tRkXCumesgO0cmw8HHarl0OoQ8mzIq4o+EE8C1hQd:ZuesY3Cn8y1mRbumbh8Hf7o+EIQd
TLSH T143035C6AA3DB014EC839CBF8D92147B3D976B0C0A01893CE5B72C9296F2E1D16374DB5
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe SolarisLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
191
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_9b30f3c425c9eb4d4bf7d6bca07b82f5f63fbcc92a43e0885b2e7613d76d7a1d.exe
Verdict:
Malicious activity
Analysis date:
2026-06-23 10:32:21 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
ransomware emotet virus remo
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Searching for synchronization primitives
Sending an HTTP GET request to an infection source
Creating a file in the %temp% directory
Enabling the 'hidden' option for files in the %temp% directory
Creating a process from a recently created file
Launching a process
Using the Windows Management Instrumentation requests
Sending an HTTP POST request
Connection attempt to an infection source
Query of malicious DNS domain
Enabling autorun by creating a file
Unauthorized injection to a system process
Sending an HTTP POST request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
explorer lolbin microsoft_visual_cc obfuscated overlay
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-26T01:12:00Z UTC
Last seen:
2026-06-03T04:26:00Z UTC
Hits:
~10
Result
Threat name:
Clipboard Hijacker, REMUS Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Changes the view of files in windows explorer (hidden files and folders)
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Creates a thread in another existing process (thread injection)
Found direct / indirect Syscall (likely to bypass EDR)
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Searches for specific processes (likely to inject)
Sigma detected: Suspicious Process Parents
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected Clipboard Hijacker
Yara detected REMUS Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1932500 Sample: wWoXTDiHAx.exe Startdate: 23/06/2026 Architecture: WINDOWS Score: 100 99 cegikmoqsuwyacegikmoqsuwy02468acegikmoqsuwyacegikmoqsuwy.com 2->99 101 youngel.biz 2->101 107 Suricata IDS alerts for network traffic 2->107 109 Malicious sample detected (through community Yara rule) 2->109 111 Antivirus detection for URL or domain 2->111 113 6 other signatures 2->113 11 wWoXTDiHAx.exe 2 11 2->11         started        16 winhost.exe 9 2->16         started        18 jusched.exe 2->18         started        20 3 other processes 2->20 signatures3 process4 dnsIp5 105 62.60.226.159, 49690, 49691, 49692 FEMOITGB Germany 11->105 83 C:\Users\user\AppData\Roaming\...\winhost.exe, PE32+ 11->83 dropped 85 C:\Users\user\AppData\Local\...\a7o90b5r.exe, PE32+ 11->85 dropped 87 C:\Users\user\...\winhost.exe:Zone.Identifier, ASCII 11->87 dropped 133 Found evasive API chain (may stop execution after checking mutex) 11->133 135 Found stalling execution ending in API Sleep call 11->135 137 Changes the view of files in windows explorer (hidden files and folders) 11->137 145 7 other signatures 11->145 22 a7o90b5r.exe 11->22         started        25 explorer.exe 43 7 11->25 injected 28 smartscreen.exe 11->28 injected 37 5 other processes 11->37 89 C:\Users\user\AppData\Local\...\8mnmwwvn.exe, PE32 16->89 dropped 139 Antivirus detection for dropped file 16->139 141 Multi AV Scanner detection for dropped file 16->141 143 Contains functionality to inject threads in other processes 16->143 30 8mnmwwvn.exe 16->30         started        33 RuntimeBroker.exe 16->33 injected 35 RuntimeBroker.exe 4 16->35 injected file6 signatures7 process8 dnsIp9 115 Antivirus detection for dropped file 22->115 117 Multi AV Scanner detection for dropped file 22->117 119 Contains functionality to inject code into remote processes 22->119 123 3 other signatures 22->123 39 notepad.exe 22->39         started        103 150.171.28.12, 443 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 25->103 121 Found evasive API chain (may stop execution after checking mutex) 25->121 97 C:\Users\user\AppData\Local\...\8mnmwwvn.tmp, PE32 30->97 dropped 43 8mnmwwvn.tmp 30->43         started        file10 signatures11 process12 file13 65 C:\Users\user\...\k1TosNomomy78X2VD0.exe, PE32+ 39->65 dropped 67 C:\Users\...\Pg6oLTBTmBR0FT0wHqNk6X6Xoq4.exe, PE32 39->67 dropped 69 C:\...\BHTaL6s33mNB7RD2qu9u4Jm7gV4iZa.exe, PE32+ 39->69 dropped 125 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 39->125 127 Tries to steal Mail credentials (via file / registry access) 39->127 129 Tries to harvest and steal ftp login credentials 39->129 131 4 other signatures 39->131 45 BHTaL6s33mNB7RD2qu9u4Jm7gV4iZa.exe 39->45         started        49 Pg6oLTBTmBR0FT0wHqNk6X6Xoq4.exe 39->49         started        51 k1TosNomomy78X2VD0.exe 39->51         started        71 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 43->71 dropped 53 8mnmwwvn.exe 43->53         started        signatures14 process15 file16 91 C:\Users\user\AppData\Local\...\jusched.exe, PE32+ 45->91 dropped 147 Antivirus detection for dropped file 45->147 149 Multi AV Scanner detection for dropped file 45->149 55 jusched.exe 45->55         started        93 C:\Users\...\Pg6oLTBTmBR0FT0wHqNk6X6Xoq4.tmp, PE32 49->93 dropped 57 Pg6oLTBTmBR0FT0wHqNk6X6Xoq4.tmp 49->57         started        95 C:\Users\user\AppData\Local\...\8mnmwwvn.tmp, PE32 53->95 dropped 60 8mnmwwvn.tmp 53->60         started        signatures17 process18 file19 73 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 57->73 dropped 75 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 60->75 dropped 77 C:\ProgramData\...\vcruntime140_1.dll (copy), PE32+ 60->77 dropped 79 C:\ProgramData\...\vcruntime140.dll (copy), PE32+ 60->79 dropped 81 10 other malicious files 60->81 dropped 62 FnHotkeyUtility.exe 60->62         started        process20 signatures21 151 Searches for specific processes (likely to inject) 62->151 153 Potentially malicious time measurement code found 62->153
Gathering data
Threat name:
Win64.Trojan.MintPhil
Status:
Malicious
First seen:
2026-05-26 10:39:07 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
29 of 36 (80.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Executes dropped EXE
Unpacked files
SH256 hash:
9b30f3c425c9eb4d4bf7d6bca07b82f5f63fbcc92a43e0885b2e7613d76d7a1d
MD5 hash:
0879e5569c1331665eabd5ab96b22c3d
SHA1 hash:
dfcd9d67757f58cfd53719718239dd00bb1e39e2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_ReflectiveLoader
Author:ditekSHen
Description:Detects Reflective DLL injection artifacts
Rule name:Malw_Solaris_Loader
Author:Nikos 'n0t' Totosis
Description:Detects Solaris Loader
Rule name:ReflectiveLoader
Author:Florian Roth (Nextron Systems)
Description:Detects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommended
Reference:Internal Research
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Description:Rule for beacon reflective loader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments