MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a36dfca12c70894f05c305cc6b19fadd505f50a5ea4672bf616397f933f38d5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 3 File information Comments

SHA256 hash: a36dfca12c70894f05c305cc6b19fadd505f50a5ea4672bf616397f933f38d5d
SHA3-384 hash: 864f108ab880afa610bb317874a74ab74158ab2fe7124b9add33803cc66d3b9b455195fbf10d359b3535ad1eb1a16cc0
SHA1 hash: 6efaf314f9f2abd6e21a83b51fbe646228bac700
MD5 hash: 066ed94d70a02ea2fc2333e6e76efd19
humanhash: arkansas-harry-nine-london
File name:a36dfca12c70894f05c305cc6b19fadd505f50a5ea4672bf616397f933f38d5d
Download: download sample
File size:946'688 bytes
First seen:2026-06-08 09:25:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'131 x AgentTesla, 20'159 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 12288:yhg5sKvieNCvdiO4mWCbZlYfm5K8nizLQJwv+esJpmv5odwAKoGXaW1LEtn:hHVNo8ZmWCllVkoav+HJpddwAKoGXaQ
TLSH T1F315E0215E876F99E63F0B7CC0124450B3F0D847D397CBAB6FED14B919A2B88CD26592
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
virus msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file
Launching a service
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
crypt obfuscated obfuscated packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-08T16:04:00Z UTC
Last seen:
2026-06-10T04:05:00Z UTC
Hits:
~1000
Malware family:
Malicious Packer
Verdict:
Malicious
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-08 19:39:28 UTC
AV detection:
14 of 18 (77.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious use of AdjustPrivilegeToken
System Location Discovery: System Language Discovery
.NET Reactor proctector
Unpacked files
SH256 hash:
a36dfca12c70894f05c305cc6b19fadd505f50a5ea4672bf616397f933f38d5d
MD5 hash:
066ed94d70a02ea2fc2333e6e76efd19
SHA1 hash:
6efaf314f9f2abd6e21a83b51fbe646228bac700
SH256 hash:
7fd74295e95ddbae4b01b8fab40da7821952fc12fc707429ba500e8048089ad2
MD5 hash:
c854e8bfbb8299bc08429b09367dc463
SHA1 hash:
6f07b0f83f02b8e92ce5c1655528cfaa85a97bfe
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments