🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a37af7c0adf4fac302b73f39b423319c1ebd808ff0c91bf7b451489119e44a3b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a37af7c0adf4fac302b73f39b423319c1ebd808ff0c91bf7b451489119e44a3b
SHA3-384 hash: 3c9866d28a85a01c5ecc0cf77f495f782456cd16e310cef1bdcfe0475193ccb1810e6a6856cc2e0a5b82b03ecad90278
SHA1 hash: ecf48456835bd4bc0b33a70c08f60c639bdc1183
MD5 hash: fe11ac54ec706806f4f65b6c32ccb8a1
humanhash: missouri-michigan-lima-pizza
File name:ProtobufLite.dll
Download: download sample
File size:150'887'296 bytes
First seen:2026-09-23 16:01:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ad9fe34fe5f9267ff1c10d689801a190
ssdeep 393216:Pq43p9CrNhfwyGeISASXc7kVpnZTNz1IJ0grPlCJqhxhkjS76ydzkUB0WDtg:ghf1LI4X7pnpNmJRJCJ6ajad4WDO
TLSH T11478AFB273C4EEFAC041D97A5705F23181A2996E8BB691C46F92870A5DF5A114F3CBCC
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Parper
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-09-23T12:59:00Z UTC
Last seen:
2026-09-23T13:51:00Z UTC
Hits:
~10
Detections:
Trojan.Win64.Agent.sb HEUR:Trojan.Win64.Aotnet.gen
Gathering data
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-09-23 16:02:28 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments