🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b23943dc5ab42e339bbc5a83bb1fa95b2bae70e7b00a8070d0de489ba9731b7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 13


Intelligence 13 IOCs YARA File information Comments

SHA256 hash: b23943dc5ab42e339bbc5a83bb1fa95b2bae70e7b00a8070d0de489ba9731b7b
SHA3-384 hash: b1fb32c4430229173c1d184de4d622814e4b9091f6c1f4d54e8f6d63022a44723b85af78fd51e6000f3ff32606f2fd17
SHA1 hash: 870f22c415f3c9d5a599ed21c2854b688aa233a4
MD5 hash: 22cebd3ccdd8efab543383d38df54381
humanhash: uniform-oscar-hamper-island
File name:file
Download: download sample
File size:18'432 bytes
First seen:2026-09-12 22:22:20 UTC
Last seen:2026-09-13 05:23:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash edd9caae8565fbe43a73e0ad530f325e (84 x Phorpiex, 15 x Phorphiex, 2 x PhantomStealer)
ssdeep 192:z5Y86SCngTBv8vVaFXq651ln5aZuyMGleQJrQKUSiu9zwDi7sVTgbOBqmEiLFTGS:zz6I8vVaF6OjGUQgu94irUwav8U9cEl
TLSH T1B5824B0FB8428316E0D11070A676827BE979A87A37C814DBF7D449DD0A786D5FC3215F
TrID 34.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
13.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
13.7% (.EXE) Win64 Executable (generic) (6522/11/2)
10.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-phorpiex exe


Avatar
Bitsight
url: http://178.16.54.109/3.exe

Intelligence


File Origin
# of uploads :
17
# of downloads :
163
Origin country :
US US
Vendor Threat Intelligence
Gathering data
Malware family:
phorpiex
ID:
1
File name:
63d87d4569a491553e14757dc267aa29ae8b606b0396dd16acc5c642f629fc7e.exe
Verdict:
Malicious activity
Analysis date:
2026-09-12 22:15:27 UTC
Tags:
loader phorpiex botnet xor-url generic ip-check auto coinminer miner xmrig

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug crypto evasive fingerprint microsoft_visual_cc obfuscated phorpiex xor-url xor-url
Verdict:
Unknown
File Type:
PE
First seen:
2026-09-12T19:11:00Z UTC
Last seen:
2026-09-12T19:11:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Worm.Phorpiex
Status:
Malicious
First seen:
2026-09-12 22:23:37 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
29 of 36 (80.56%)
Threat level:
  5/5
Gathering data
Unpacked files
SH256 hash:
b23943dc5ab42e339bbc5a83bb1fa95b2bae70e7b00a8070d0de489ba9731b7b
MD5 hash:
22cebd3ccdd8efab543383d38df54381
SHA1 hash:
870f22c415f3c9d5a599ed21c2854b688aa233a4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe b23943dc5ab42e339bbc5a83bb1fa95b2bae70e7b00a8070d0de489ba9731b7b

(this sample)

  
Dropped by
Phorpiex
  
Delivery method
Distributed via web download

Comments