🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a19fce7dfd85822b3dcc3fad77b0d91ac2740fc5a739f5741a1d3294ca2135bb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a19fce7dfd85822b3dcc3fad77b0d91ac2740fc5a739f5741a1d3294ca2135bb
SHA3-384 hash: 50a11feb81db68b4cc87cb13e1624c9b30d4a2c7514cf16eef1e168f50e68cfe8798205d5582f15efd629da1bc0576eb
SHA1 hash: a93c087ff20cfbb42937c7e8c102d562c215a6ae
MD5 hash: 6b2fbfab939314234562e355acf91af3
humanhash: helium-island-india-shade
File name:Loader.exe
Download: download sample
File size:97'949'184 bytes
First seen:2026-09-08 22:20:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fd6f6d07cc33ee9a2b65bda58a07bb94 (10 x NWHStealer)
ssdeep 1572864:GZa7hmguP2nG0/Vyv7UhgxIabc/97Awb0:GZa7hmguP2nUOTAwb0
TLSH T146286C43A2E751D8F0BBD17496E65323E933BC490B3469EF12944B312F72AE0A779B11
TrID 55.7% (.WLX) Total Commander Lister extension (plugin) (21500/1/6)
16.9% (.EXE) Win64 Executable (generic) (6522/11/2)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
5.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9170cc9296cc7001 (10 x NWHStealer, 1 x XWorm)
Reporter burger
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-08 22:29:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug fingerprint obfuscated overlay packed reconnaissance rust
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
96 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
PE file contains section with special chars
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1970418 Sample: Loader.exe Startdate: 09/09/2026 Architecture: WINDOWS Score: 96 28 t.me 2->28 30 nikobosst.cc 2->30 32 3 other IPs or domains 2->32 54 Malicious sample detected (through community Yara rule) 2->54 56 Antivirus detection for URL or domain 2->56 58 PE file contains section with special chars 2->58 60 Joe Sandbox ML detected suspicious sample 2->60 9 Loader.exe 2->9         started        signatures3 process4 dnsIp5 36 nightly-sun.cc 104.21.57.89, 443, 49714 CLOUDFLARENET-CloudflareIncUS Canada 9->36 38 api.ipify.org 104.26.12.205, 443, 49711 CLOUDFLARENET-CloudflareIncUS Canada 9->38 40 3 other IPs or domains 9->40 62 Bypasses PowerShell execution policy 9->62 64 Tries to harvest and steal browser information (history, passwords, etc) 9->64 66 Writes to foreign memory regions 9->66 68 5 other signatures 9->68 13 chrome.exe 1 9->13         started        16 powershell.exe 14 15 9->16         started        18 msedge.exe 4 9->18         started        signatures6 process7 dnsIp8 48 t.me 149.154.167.99, 443, 49716 TELEGRAMVG United Kingdom 13->48 50 nikobosst.cc 104.21.74.153, 443, 49717 CLOUDFLARENET-CloudflareIncUS Canada 13->50 20 chrome.exe 2 13->20         started        52 bun.report 104.21.5.173, 443, 49734 CLOUDFLARENET-CloudflareIncUS Canada 16->52 23 conhost.exe 16->23         started        process9 dnsIp10 34 192.168.2.4, 138, 443, 49698 unknown unknown 20->34 25 chrome.exe 20->25         started        process11 dnsIp12 42 142.251.151.119, 443, 49723, 49726 GOOGLE-GoogleLLCUS United States 25->42 44 www.google.com 142.251.156.119, 443, 49720, 49728 GOOGLE-GoogleLLCUS United States 25->44 46 4 other IPs or domains 25->46
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Maps connected drives based on registry
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments