MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b31e6a580a92375e40e3bfedfaa48c50e28e0073a45f530b3b2e9426764cee2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DonutLoader


Vendor detections: 10


Intelligence 10 IOCs YARA 12 File information Comments

SHA256 hash: b31e6a580a92375e40e3bfedfaa48c50e28e0073a45f530b3b2e9426764cee2f
SHA3-384 hash: b9c098ed1062fb80175c391f01e479d529bc64a41d9688b5c22a64a25ac5f2d4edfe3e929be3c86180f6ba157c00aa91
SHA1 hash: 723e3d1155d93f34dad9af1ba356c2b58dc36a1f
MD5 hash: 9bd0e8c15daebea799c43622dedd3f45
humanhash: jupiter-kitten-romeo-helium
File name:SafeWitopd_2631625632.zip
Download: download sample
Signature DonutLoader
File size:56'796'705 bytes
First seen:2026-03-16 17:23:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 786432:mVQMTp0dxWmHf98UpZfuOaEV7P+1Y3yIlR4gv1//ECagcW7vVH7K0M3Ki66KdR+m:mVv0dH8gfDP+KDRt9//dagc0vJIVQP
TLSH T1E4C73336E4E7639A6FEBF912D05477A29345375C0028DCB6E3A133D07752BD024BAA93
Magika zip
Reporter juroots
Tags:donutloader zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
CZ CZ
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:SafeWitopd_2631625632.msi
File size:58'267'648 bytes
SHA256 hash: d0777545f6d924861d65bcb358f6a22e9d69f1b2b482e005bac4914db65b8471
MD5 hash: 424eb9d94ef8f016527c98abe4eb46ef
MIME type:application/x-msi
Signature DonutLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
shellcode virus blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm at base64 CAB cmd datper expand expired-cert fingerprint installer large-file lolbin lolbin overlay packed tracker wix
Gathering data
Threat name:
Win32.Exploit.DonutMarte
Status:
Malicious
First seen:
2026-03-16 13:43:36 UTC
File Type:
Binary (Archive)
Extracted files:
55
AV detection:
9 of 22 (40.91%)
Threat level:
  5/5
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:donutloader discovery execution loader persistence privilege_escalation ransomware
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Enumerates connected drives
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Detects DonutLoader
DonutLoader
Donutloader family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_MSI_LATAM_Banker_From_LatAm
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DonutLoader

zip b31e6a580a92375e40e3bfedfaa48c50e28e0073a45f530b3b2e9426764cee2f

(this sample)

  
Delivery method
Distributed via web download

Comments