MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b34e63a19450f6b9cf78c4bd3be1bf5cb38b1d3d02a63ffb10fbcaa3a1a9e724. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: b34e63a19450f6b9cf78c4bd3be1bf5cb38b1d3d02a63ffb10fbcaa3a1a9e724
SHA3-384 hash: a90688b228a7a9764843c6bc431c540482efde894f681be9fd57bef11b5358b7d620f055f2c7fc11b7f78092d4b164a2
SHA1 hash: b4a2ddde5fc7dd8ae5b1bd5a74dbc177dec2b437
MD5 hash: eefaf56cee585252e5ba15622d118146
humanhash: purple-winter-leopard-floor
File name:b34e63a19450f6b9cf78c4bd3be1bf5cb38b1d3d02a63ffb10fbcaa3a1a9e724
Download: download sample
File size:556'648 bytes
First seen:2026-08-10 14:35:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9be4f90f50c714bc00cc8beb2e137299 (6 x RemcosRAT, 3 x Formbook)
ssdeep 12288:170ZdexqurywS6jH5rAo3d3E/YaNC8Nb2Dnqnq5W:17QexbrZxjH5rA+d0/Gy2DnLW
TLSH T114C4F147AB9217AEF8267CFCCDEBC92363617F565564524B0600DE2E78E7490C42BE32
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 272396d4c098d0d0
Reporter adrian__luca
Tags:exe signed

Code Signing Certificate

Organisation:Rumina
Issuer:Rumina
Algorithm:sha256WithRSAEncryption
Valid from:2026-05-28T09:27:48Z
Valid to:2027-05-28T09:27:48Z
Serial number: 1cf26090659257e65d3be2b3d2be81da4ad1ba37
Thumbprint Algorithm:SHA256
Thumbprint: edfa9f3029c1f5ecbf7f833497282db7d83cd4c9f31b4061a9b2cfb704ef2ebc
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Creating a file
Delayed reading of the file
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug fingerprint installer installer installer-heuristic nsis packed reconnaissance signed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-21T05:44:00Z UTC
Last seen:
2026-08-12T07:56:00Z UTC
Hits:
~1000
Gathering data
Gathering data
Threat name:
Win64.Malware.Heuristic
Status:
Malicious
First seen:
2026-07-21 14:44:01 UTC
File Type:
PE+ (Exe)
Extracted files:
11
AV detection:
22 of 36 (61.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Loads dropped DLL
Unpacked files
SH256 hash:
b34e63a19450f6b9cf78c4bd3be1bf5cb38b1d3d02a63ffb10fbcaa3a1a9e724
MD5 hash:
eefaf56cee585252e5ba15622d118146
SHA1 hash:
b4a2ddde5fc7dd8ae5b1bd5a74dbc177dec2b437
SH256 hash:
c7dd8cc8323e295b8821b0e320de208a7e20c068a8be8d03857520451ce9ded7
MD5 hash:
4abf19a47044ec746aa8c600f0bc149f
SHA1 hash:
69da1e4f654b044d7b3c845c12a07c988bf26eb8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments