MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b4e4250fdfb3a7398edc10be74a79e29100460d6a2d0bef99e4f5411a2dbe68a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
DCAgentRMM
Vendor detections: 5
| SHA256 hash: | b4e4250fdfb3a7398edc10be74a79e29100460d6a2d0bef99e4f5411a2dbe68a |
|---|---|
| SHA3-384 hash: | 11a6e3d69156f9306ccc85f8527b4f78eac702b975b254674437307ace86e5bfd5b478d3feb3a6c5e6bf502e43c24a2f |
| SHA1 hash: | e388856e400f1c411e487569b29e6036b894c027 |
| MD5 hash: | d369787c271fb53555658d49ae450ff8 |
| humanhash: | mexico-neptune-nebraska-maine |
| File name: | T.No20260921.dll |
| Download: | download sample |
| Signature | DCAgentRMM |
| File size: | 82'320 bytes |
| First seen: | 2026-09-23 22:08:45 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 61b57217c8593297b9ca90779708b7c2 (2 x DCAgentRMM) |
| ssdeep | 1536:Gb4s6VomsoDosxZJFy55TaaqpJBcnnjeCnF8tbQ+unNKc:Gb4s6VBQdGJiSCnWm+et |
| TLSH | T1C4833923F6A625ECC92BC531CAEB9633EEB1B44805255F3F5510CA313E61EA06F6DB14 |
| TrID | 33.1% (.EXE) Win64 Executable (generic) (6522/11/2) 25.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 10.4% (.ICL) Windows Icons Library (generic) (2059/9) 10.3% (.EXE) OS/2 Executable (generic) (2029/13) 10.1% (.EXE) Generic Win/DOS Executable (2002/3) |
| Magika | pebin |
| Reporter | |
| Tags: | Certum DCAgentRMM exe msi signed T.No |
Code Signing Certificate
| Organisation: | Xidao E-commerce Studio, Yishui County |
|---|---|
| Issuer: | Certum Extended Validation Code Signing 2021 CA |
| Algorithm: | sha256WithRSAEncryption |
| Valid from: | 2026-08-25T12:53:52Z |
| Valid to: | 2027-08-25T12:53:51Z |
| Serial number: | 7836fc681aae72e82815b7a3654dbf01 |
| Intelligence: | 2 malware samples on MalwareBazaar are signed with this code signing certificate |
| MalwareBazaar Blocklist: | This certificate is on the MalwareBazaar code signing certificate blocklist (CSCB) |
| Cert Graveyard Blocklist: | This certificate is on the Cert Graveyard blocklist |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | 6ca6f0d9d0b33c68334ee47eeafa0040990320deaaae5ba23b946c5e93ff671e |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
devmihaylov
Certum EV-signed 64-bit MinGW DLL with per-string XOR-obfuscated strings and hash-resolved APIs, which downloads a SHA-256-checked ZIP over WinHTTP and silently installs a signed MSI behind a CMSTPLUA/computerdefaults UAC bypass. The MSI is the genuine ZOHO-signed ManageEngine Endpoint Central agent, pre-configured by a bundled JSON to enroll the host into the attacker's own server at 134.122.200.153:8151 and to trust two attacker root CAs.Intelligence
File Origin
BGVendor Threat Intelligence
Result
Result
Behaviour
Unpacked files
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | certum_issuer |
|---|---|
| Author: | Certum |
| Description: | Looks for files signed with certificate issued by Certum |
| Rule name: | detect_certum_issuer |
|---|---|
| Author: | Certum |
| Description: | Looks for files signed with certificate issued by Certum |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | pe_detect_tls_callbacks |
|---|
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
8b69caa53168f4e3701e8d8ce8b30f610ff74b6517a584ba02a3d86e132d1ad3
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.