🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab21f534e2d446aafdc6a1fd6cfb77ea3d2d25a9ca78f6cceee27f05f87cf0da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DCAgentRMM


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: ab21f534e2d446aafdc6a1fd6cfb77ea3d2d25a9ca78f6cceee27f05f87cf0da
SHA3-384 hash: 7dcc189604957ef755fde5c39cb3a6d7c1180fbacc55c6531151010e4452ce7885e3865d3d4aa8bff5c402443fa2e22c
SHA1 hash: f464147c7e6088eefa486598992affff9baccfc7
MD5 hash: 6971fe8968925a2c0617db0f4714a27f
humanhash: monkey-july-berlin-table
File name:ARPHADUMP.dll
Download: download sample
Signature DCAgentRMM
File size:18'944 bytes
First seen:2026-10-06 07:26:40 UTC
Last seen:Never
File type:DLL dll
MIME type:application/vnd.microsoft.portable-executable
imphash ac6471cdaced8dba75cda30e7b659cdf (1 x DCAgentRMM)
ssdeep 384:j2MiBgAOWjvZoqMA/1y29nFxgOKhplf5Nk3HYzN2I+fI:KNFbZmsFWhphk32N
TLSH T128822B0EF602ACF5EC5786B99CCBE7B7C6D1620540592AFAFB4CC24C7A61B40ED0A547
TrID 21.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
21.2% (.EXE) Win64 Executable (generic) (6522/11/2)
16.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
14.6% (.EXE) Win32 Executable (generic) (4504/4/1)
6.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter smica83
Tags:DCAgentRMM dll

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Malicious
File Type:
dll x32
First seen:
2026-10-06T01:00:00Z UTC
Last seen:
2026-10-06T10:48:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Changes security center settings (notifications, updates, antivirus, firewall)
Enables network access during safeboot for specific services
Encrypted powershell cmdline option found
Installs new ROOT certificates
Joe Sandbox ML detected suspicious sample
Potential context-aware VBS script found (checks for environment specific values)
Powershell connects to network
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Malicious Base64 Encoded PowerShell Keywords in Command Lines
Sigma detected: PowerShell Base64 Encoded Invoke Keyword
Sigma detected: Powerup Write Hijack DLL
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Sigma detected: Suspicious PowerShell Invocations - Generic - PowerShell Module
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious powershell command line found
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes or reads registry keys via WMI
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1982807 Sample: ARPHADUMP.dll Startdate: 06/10/2026 Architecture: WINDOWS Score: 100 92 kkk.tttkkkssww.com 2->92 100 Yara detected Powershell download and execute 2->100 102 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 2->102 104 Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines) 2->104 106 10 other signatures 2->106 9 msiexec.exe 2->9         started        13 loaddll32.exe 1 2->13         started        15 dcagentservice.exe 2->15         started        17 9 other processes 2->17 signatures3 process4 dnsIp5 72 C:\Program Files (x86)\...\dcconfig.exe, PE32 9->72 dropped 74 C:\...\dcagentregister.exe, PE32 9->74 dropped 76 C:\Windows\SysWOW64\dclibxml2.dll, PE32 9->76 dropped 78 16 other files (none is malicious) 9->78 dropped 116 Potential context-aware VBS script found (checks for environment specific values) 9->116 20 dcagentregister.exe 9->20         started        24 msiexec.exe 9->24         started        118 Suspicious powershell command line found 13->118 120 Encrypted powershell cmdline option found 13->120 122 Bypasses PowerShell execution policy 13->122 26 powershell.exe 15 53 13->26         started        29 cmd.exe 1 13->29         started        37 12 other processes 13->37 31 dcinventory.exe 15->31         started        33 dcusbsummary.exe 15->33         started        39 5 other processes 15->39 90 127.0.0.1 unknown unknown 17->90 124 Changes security center settings (notifications, updates, antivirus, firewall) 17->124 35 conhost.exe 17->35         started        file6 signatures7 process8 dnsIp9 94 134.122.155.183, 49710, 49712, 49713 CTGSERVERLIMITED-AS-APCTGServerLimitedHK Japan 20->94 108 Installs new ROOT certificates 20->108 110 Enables network access during safeboot for specific services 20->110 41 7za.exe 20->41         started        45 cmd.exe 20->45         started        47 dcstatusutil.exe 20->47         started        96 kkk.tttkkkssww.com 104.194.155.90, 443, 49707 ROUTERHOSTING-RouterHostingLLCUS Singapore 26->96 88 C:\Users\Public\Documents\...\setup.bat, DOS 26->88 dropped 112 Powershell connects to network 26->112 49 conhost.exe 26->49         started        51 msiexec.exe 26->51         started        53 rundll32.exe 29->53         started        98 134.122.155.188, 49723, 49724, 49725 CTGSERVERLIMITED-AS-APCTGServerLimitedHK Japan 31->98 114 Tries to detect sandboxes / dynamic malware analysis system (Installed program check) 31->114 55 conhost.exe 31->55         started        57 dcusb64.exe 33->57         started        59 5 other processes 39->59 file10 signatures11 process12 file13 80 C:\Program Files (x86)\...\dcstatusutil.exe, PE32 41->80 dropped 82 C:\Program Files (x86)\...\dcinventory.exe, PE32 41->82 dropped 84 C:\Program Files (x86)\...\wsClientSocket.dll, PE32 41->84 dropped 86 69 other files (none is malicious) 41->86 dropped 126 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 41->126 61 conhost.exe 41->61         started        63 systeminfo.exe 45->63         started        66 conhost.exe 45->66         started        68 conhost.exe 47->68         started        70 conhost.exe 57->70         started        signatures14 process15 signatures16 128 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 63->128 130 Writes or reads registry keys via WMI 63->130
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.AdvML
Status:
Malicious
First seen:
2026-10-06 07:27:21 UTC
File Type:
PE (Dll)
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
ab21f534e2d446aafdc6a1fd6cfb77ea3d2d25a9ca78f6cceee27f05f87cf0da
MD5 hash:
6971fe8968925a2c0617db0f4714a27f
SHA1 hash:
f464147c7e6088eefa486598992affff9baccfc7
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

DCAgentRMM

DLL dll ab21f534e2d446aafdc6a1fd6cfb77ea3d2d25a9ca78f6cceee27f05f87cf0da

(this sample)

Comments