MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1e14e2b06dc859053cb63cfa9e76b4ef43540a35d736dc9fb1c39986bf67654. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 7


Intelligence 7 IOCs YARA 22 File information Comments

SHA256 hash: a1e14e2b06dc859053cb63cfa9e76b4ef43540a35d736dc9fb1c39986bf67654
SHA3-384 hash: 59a190675ac9d686b8168f6dfeee785471a22a4553ac96e7869fc4221b25ee56105ad733ef0c058b6e852c392460f939
SHA1 hash: ca1217edf2d141cafd819a622589fccc89cd40e5
MD5 hash: 37a499bf29ea274a9482a3383c3d06b1
humanhash: vegan-hotel-oscar-wolfram
File name:package
Download: download sample
Signature KongTuke
File size:17'467'430 bytes
First seen:2026-07-20 15:11:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:J/zDs0zdBadqZxrJUZLpNHK8MZGm0D0IxmJwcX1iFi19:9/s0zdBaSxrEpNHKTrJ1gc19
TLSH T1850733DE60E0617FE04CF618F8CA1BE8E9210C8893D35C91DB2775A5A427B96C776E43
TrID 66.6% (.FB2K-COMPONENT) foobar2000 component (8000/1/2)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter monitorsg
Tags:Kongtuke zip


Avatar
monitorsg
hXXps://meduurst[.]space/vtyzese3.js (ClickFucker) --> hXXps://meduurst[.]space/api/v1/session (token) --> hXXps://meduurst[.]space/api/v1/verify (gateway) --> hXXps://meduurst[.]space/api/v1/status (clipboard) --> hXXps://nodemetrics9095[.]com/update/package (tar)

Intelligence


File Origin
# of uploads :
1
# of downloads :
207
Origin country :
US US
File Archive Information

This file archive contains 21 file(s), sorted by their relevance:

File name:xul.dll
File size:8'611'840 bytes
SHA256 hash: b315c20b622bcd7be62f8e180a1cf1e4d7b938c7729311a84dfbab9e6e55938f
MD5 hash: 753eb5bc9aaea53f71712e717861b919
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.manifest
File size:240 bytes
SHA256 hash: 23680bbba9edbbfab98e27f9bd676b031da3b20adfe909ce86c9ecc1b8bb80d1
MD5 hash: 5d5e62ad6d1023592406fe3ea1f0ea75
MIME type:text/xml
Signature KongTuke
File name:vcruntime140_1.dll
File size:47'264 bytes
SHA256 hash: e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
MD5 hash: 03b43160d21c08de07a79d0a1c5ee81d
MIME type:application/x-dosexec
Signature KongTuke
File name:AccessibleMarshal.dll
File size:936'448 bytes
SHA256 hash: 19b3ed743bdcb74315b145571f4c967913071bb550d296a208f052aba10e597e
MD5 hash: 1d112907be3ed5f411c3f38832b3e299
MIME type:application/x-dosexec
Signature KongTuke
File name:gkcodecs.dll
File size:936'448 bytes
SHA256 hash: f84a46bb597e1653bf5b58c7bac0ccebeb3c1b61a6f20ac2da0605ad2cdc8ca6
MD5 hash: 1d329e6e7ef4f0e3099229559ee203a4
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.dll
File size:6'480'384 bytes
SHA256 hash: 09aae37bdcdd9a934fecb87f8fe780a0effb91c500449b676409a55f7b7e0152
MD5 hash: 85b9b94ca07107af52429a794b36be29
MIME type:application/x-dosexec
Signature KongTuke
File name:plugin-container.exe
File size:144'512 bytes
SHA256 hash: b2f2b9a3a712125a06b303344b7a0dc57f91ee6f1749c731ca2260931dbe24e9
MD5 hash: 65729157b053d4d373595f7a53126298
MIME type:application/x-dosexec
Signature KongTuke
File name:wmfclearkey.dll
File size:882'688 bytes
SHA256 hash: e6ede8d4545ff5543b9a556cfd61ab3569adab77d47c1d47155e9e177623172b
MD5 hash: 853b80ed3db02b2487523572186033a8
MIME type:application/x-dosexec
Signature KongTuke
File name:freebl3.dll
File size:936'448 bytes
SHA256 hash: 3ece6888809b1d2c27cd4f698a21ca337557bd33c0693c83292b0bb5372db62d
MD5 hash: b5ba63ad9c906eae84a3582a229dc5c0
MIME type:application/x-dosexec
Signature KongTuke
File name:mozinference.dll
File size:936'448 bytes
SHA256 hash: e7d54cbc76f0a9ebd3749238b971b4b396a557a5f2e8425f5f0b9a183381d152
MD5 hash: 6b466e82b5aecdc6e9c3094262c7f4b2
MIME type:application/x-dosexec
Signature KongTuke
File name:vcruntime140.dll
File size:123'472 bytes
SHA256 hash: 184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
MD5 hash: 0d35c5e99871b4f02c490b9fd9dace34
MIME type:application/x-dosexec
Signature KongTuke
File name:nss3.dll
File size:936'448 bytes
SHA256 hash: 1d6562bfac563b48f96a937220c5e954371d54e6abf8b4bf84e4a9f6afbecbd0
MD5 hash: 6e5d9b686261c875f74514ad251b438d
MIME type:application/x-dosexec
Signature KongTuke
File name:libEGL.dll
File size:3'075'584 bytes
SHA256 hash: 1b91577d66a8768350e18cb1dd6024917c41d105f92bd9ce6ca7bf04c1c619b0
MD5 hash: 78dfaaaf6e8107807aa6c357e6dbe118
MIME type:application/x-dosexec
Signature KongTuke
File name:libGLESv2.dll
File size:3'082'752 bytes
SHA256 hash: e3eaa44a9bf5a6e37e7e913136688435d2b70bddd55221b7c67cc1fd1642e6bb
MD5 hash: e2a109980c899c33f482ef8d633192af
MIME type:application/x-dosexec
Signature KongTuke
File name:notificationserver.dll
File size:2'818'048 bytes
SHA256 hash: a9088eff7837e6bf2c57938e010469a596c87098145807c2673a35d6a1219d73
MD5 hash: 7f94de9e4ef1d01bb1837e468c177fae
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavcodec.dll
File size:1'099'264 bytes
SHA256 hash: 71330e7e506e9f833f5bdda7e30d804959af0034420a92a26aef3e50d05ee663
MD5 hash: 94dc6e33ff3603fb5e3f171c8b06b00b
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavutil.dll
File size:3'074'560 bytes
SHA256 hash: ca6e7ba5e236ef570655ba40fe9eee6a86227a745031db6b711d91d5826c19a5
MD5 hash: 7a1df9a2ae6861527ff83694b157b83f
MIME type:application/x-dosexec
Signature KongTuke
File name:msvcp140.dll
File size:553'552 bytes
SHA256 hash: def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
MD5 hash: 4e3fa9bd90ef020c14359639dc19312b
MIME type:application/x-dosexec
Signature KongTuke
File name:mozwer.dll
File size:936'448 bytes
SHA256 hash: 0968e8ae062915992719b3fe05b77119b1116e8d5a53e3a42006ac58fdb9dce4
MD5 hash: b10d234875d47934861a735cead6f834
MIME type:application/x-dosexec
Signature KongTuke
File name:lgpllibs.dll
File size:936'448 bytes
SHA256 hash: 1a78870414f7a045a919aab3167b62721aa8f172c3ab5bc6d1e46babc3a7b9f3
MD5 hash: 61f8457d9c490f792801a1054aafaf97
MIME type:application/x-dosexec
Signature KongTuke
File name:softokn3.dll
File size:936'960 bytes
SHA256 hash: b66b0feac139d662247675b326c70f71f63b05044c7444dd31fe4b34dbade044
MD5 hash: 30089dcba175b05fb211f27d22ce543a
MIME type:application/x-dosexec
Signature KongTuke
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
obfuscated virus
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Win_FakeInstaller_PythonShellcodeLoader_Crepectl_2026
Author:SixHands
Description:Detects the analyzed fake installer sample using .key config, XOR key, and Python/fiber shellcode loader traits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

zip a1e14e2b06dc859053cb63cfa9e76b4ef43540a35d736dc9fb1c39986bf67654

(this sample)

  
Delivery method
Distributed via web download

Comments