🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3e01ecc1e0a7e485e7bb39ae0ebbb39875c4c1a39b2e9414cff53d07926f5e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: b3e01ecc1e0a7e485e7bb39ae0ebbb39875c4c1a39b2e9414cff53d07926f5e8
SHA3-384 hash: f8c31a790da500bfc33b4a93f41e0cf8dcd1f98e05e7d9b452c33540a726df3bb9e621dd1a435186309a6996b72a969a
SHA1 hash: 1f0599dad2f8fc1f8af225eb17980daa65303e04
MD5 hash: cd2d9126d52cfe4e4634facf0414a5ad
humanhash: oklahoma-maryland-pennsylvania-king
File name:b3e01ecc1e0a7e485e7bb39ae0ebbb39875c4c1a39b2e9414cff53d07926f5e8
Download: download sample
File size:1'968'640 bytes
First seen:2026-09-04 20:36:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 24576:AqUU+E0ny5Lco1GBzzPn0ATneqpwnslq0DQ6TV7b:TUU1XinLJwsv
TLSH T151957C2439FB502AB1B3EF664BE475D6DA6FB6333B07641E1091038A4723A81DED153E
TrID 34.1% (.EXE) Win64 Executable (generic) (6522/11/2)
23.5% (.EXE) Win32 Executable (generic) (4504/4/1)
10.7% (.ICL) Windows Icons Library (generic) (2059/9)
10.6% (.EXE) OS/2 Executable (generic) (2029/13)
10.4% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-04 23:02:35 UTC
Tags:
auto-reg auto-startup stealer rmrlx rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Deleting a recently created file
Launching a process
Using the Windows Management Instrumentation requests
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Unauthorized injection to a system process
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm base64 fingerprint lolbin msbuild obfuscated overlay packed reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-12T08:19:00Z UTC
Last seen:
2026-08-24T08:44:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
7 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.16 SOS: 0.35 Win 64 Exe x64
Threat name:
Win64.Packed.Generic
Status:
Suspicious
First seen:
2026-08-12 17:11:55 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
3
AV detection:
22 of 36 (61.11%)
Threat level:
  1/5
Verdict:
malicious
Label(s):
unc_dotnet_stealer_002
Result
Malware family:
lxbaserat
Score:
  10/10
Tags:
family:lxbaserat botnet:group1 campaign:853238fd1fad403894dfd7efd76af7df execution persistence privilege_escalation rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Suspicious use of SetThreadContext
Adds Run key to start application
Creates a file in the Startup directory
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: LxBaseRAT
Malware Config
C2 Extraction:
64.89.160.127:4561
Unpacked files
SH256 hash:
b3e01ecc1e0a7e485e7bb39ae0ebbb39875c4c1a39b2e9414cff53d07926f5e8
MD5 hash:
cd2d9126d52cfe4e4634facf0414a5ad
SHA1 hash:
1f0599dad2f8fc1f8af225eb17980daa65303e04
SH256 hash:
7ca7c0d114090a1c5bcd7a5d68a395434c4797a231cd13f1c7550e87dfe065f7
MD5 hash:
09632e5ffd4062d492575dacb0d615b8
SHA1 hash:
9092e681e62b6f704ea4c8ffc1e4724a83fed475
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments