MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7079163c19f0d679122ba8fcfb3de0f63727a19477ac1b66eddac530eeb21fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: a7079163c19f0d679122ba8fcfb3de0f63727a19477ac1b66eddac530eeb21fd
SHA3-384 hash: d6a6e74e5fc2c459e250ed74efc72e6062df4d6b2ca5145561e3c8b08b5808ac6e3c10478594222dc2aa2feb320c0d49
SHA1 hash: 575e1bfb74462c9149c30f73956938c21784c28d
MD5 hash: 3c7d605af2fa03db0ff0b98f6e0fcc26
humanhash: iowa-comet-east-lake
File name:a7079163c19f0d679122ba8fcfb3de0f63727a19477ac1b66eddac530eeb21fd
Download: download sample
File size:1'694'208 bytes
First seen:2026-07-07 14:28:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'150 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 49152:Wz+FjnIQMyYinkcnoLoJWQiVgBiLEP3u3uBw:VFjIQMVindtJKVfGYuBw
Threatray 381 similar samples on MalwareBazaar
TLSH T1327512586A6BD803C56503758AE0F17413B95E8AF503E21B2FED2EFF7A22B954D84343
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
NETReactor RoboSki
Details
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Connection attempt
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
net_reactor obfuscated packed packed remcosrat stealer
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-06-11T14:46:00Z UTC
Last seen:
2026-07-08T19:20:00Z UTC
Hits:
~1000
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Spynoon
Status:
Malicious
First seen:
2026-06-11 22:09:43 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Unpacked files
SH256 hash:
a7079163c19f0d679122ba8fcfb3de0f63727a19477ac1b66eddac530eeb21fd
MD5 hash:
3c7d605af2fa03db0ff0b98f6e0fcc26
SHA1 hash:
575e1bfb74462c9149c30f73956938c21784c28d
SH256 hash:
5f42eb39ab4b0bd2146a041a921ad316db253d49c0344cf307702968fd91564c
MD5 hash:
c8f5af416eba9e6338ce44f3c969b922
SHA1 hash:
2b285d87078f928d4c1338405e746e9f8d57d602
SH256 hash:
5cd2d0b0700d0d519e9c0e6156635780ce012c799452c5fe1fd3d79337f6fb5d
MD5 hash:
ee6f14f4f2654ff5188500ed598fc57a
SHA1 hash:
d5b0b6755aa05d20298342732e1f900954b6ec96
SH256 hash:
80d20017116b09bade67f1aa7315ed6ea43c30019aea1893099cfe739e8216d6
MD5 hash:
e510a8382716ddc333023e75c859dec8
SHA1 hash:
df3028908918f3c367fa4f04ffa8c9f99f8e6472
SH256 hash:
9adb66e75eba5a007b30a5b9a8ed9b7e49c86ca89430709f8974012619862265
MD5 hash:
355cd03a8a24035a179b0c67c7d38a97
SHA1 hash:
382dc23a67637918c195df65b2d3fa6613bb907c
SH256 hash:
b2a66e9864f81c2800a5afef4bfd1faf7c910e5a43ea2eb9dbb15c8ab6ffc633
MD5 hash:
f0a13fb422cdb1f3ce667df897b5045b
SHA1 hash:
9b6566603e3a292482788924a83a1d94a9cd4627
SH256 hash:
5b151970eca51570ad51f225aa5d0d7ca28a47cc3e6e91091c5650a7828c30cc
MD5 hash:
710cc807a7e488a2a16fdd8fd9fd0250
SHA1 hash:
c0b4a877542c2ed649db86d6b1272af11e23d1c5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments