🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac685c11d93323bd0d1a3bef2b9f2f1cd0b7844a8788e59be9468c3d10e2e068. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: ac685c11d93323bd0d1a3bef2b9f2f1cd0b7844a8788e59be9468c3d10e2e068
SHA3-384 hash: 41c78d1ef17f6a5ef1ab07b65005e3e643477a71640f3266a2ada2b3f5c24c517d88ef2b029696b89b47f5d6a4092beb
SHA1 hash: 72b18fe3e2e3f16d22cc5e2ba2b7c02a425ef5a3
MD5 hash: af5050d06e27ec8d0c69c166e291e01b
humanhash: yellow-fillet-table-indigo
File name:file
Download: download sample
File size:78'512'261 bytes
First seen:2026-08-10 17:17:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 70d2e884fa127843c5bcbb53da86b6c8 (9 x TrustConnect, 5 x ConnectWise, 3 x AxisControl)
ssdeep 786432:w0XviV5OtsFjFsx85vm7fR19qS+BsXJTR:raExo4fJvb9R
TLSH T1F9089E15A3EC0716D1BEC279C6628693E6B0B8951F51C2CF0459DA8D2F63FC05EFB262
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-gcleaner exe f MIX8.file


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
1
# of downloads :
248
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a file
Moving a recently created file
Creating a process from a recently created file
Launching a process
Using the Windows Management Instrumentation requests
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Enabling autorun
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug base64 base64 expand fingerprint lolbin microsoft_visual_cc msbuild net overlay overlay privilege reconnaissance reconnaissance reconnaissance tracker
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-10T15:31:00Z UTC
Last seen:
2026-08-10T16:08:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win64.Trojan.Malgent
Status:
Malicious
First seen:
2026-08-10 17:20:01 UTC
File Type:
PE+ (Exe)
Extracted files:
356
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion execution persistence privilege_escalation
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Launches sc.exe
Adds Run key to start application
Obfuscated Files or Information: Command Obfuscation
Creates a file in the Startup directory
Executes dropped EXE
Loads dropped DLL
Stops running service(s)
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe ac685c11d93323bd0d1a3bef2b9f2f1cd0b7844a8788e59be9468c3d10e2e068

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments