MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4a2be0d5f71c90379f35513a82035aefd3c1c2d9f9b454bf2da06191f13537c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 13 File information Comments

SHA256 hash: b4a2be0d5f71c90379f35513a82035aefd3c1c2d9f9b454bf2da06191f13537c
SHA3-384 hash: daf2400d623add7a0435e5101042aa736b91bffd9ade3f38a0a6151fb6218e34310a29c564630c4df7af107b4fb3eab6
SHA1 hash: b282dd0616766c73867e539e8754438e48c8a708
MD5 hash: 826792057d4671af5f336e783f427c63
humanhash: failed-three-wyoming-berlin
File name:b4a2be0d5f71c90379f35513a82035aefd3c1c2d9f9b454bf2da06191f13537c
Download: download sample
File size:1'096'704 bytes
First seen:2026-06-08 08:34:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2247728a7effe70965982babad4e9a7a
ssdeep 24576:f0JUjC6Oil0BxvVN2bUbAqkIZ+gApdnNzSjNperDrkwE00o+:f0JUjLOM03AqkIZA9A2DAF00o+
TLSH T1FD35BF16F3E405B4E63BD238CAA64233EAB678511770AECF1259D6152F33AD07B3A315
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter adrian__luca
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
99.1%
Tags:
virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto microsoft_visual_cc packed
Verdict:
Adware
File Type:
exe x64
First seen:
2026-05-24T23:51:00Z UTC
Last seen:
2026-06-10T04:05:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win64.Backdoor.Cobalt
Status:
Malicious
First seen:
2026-05-25 02:51:35 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
b4a2be0d5f71c90379f35513a82035aefd3c1c2d9f9b454bf2da06191f13537c
MD5 hash:
826792057d4671af5f336e783f427c63
SHA1 hash:
b282dd0616766c73867e539e8754438e48c8a708
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercês
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments