🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4ff59be95361d56347d381ffa917a5e583937b5c854b243e466d9d8f5bc2990. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hades


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b4ff59be95361d56347d381ffa917a5e583937b5c854b243e466d9d8f5bc2990
SHA3-384 hash: b338892732ceca9fe690b9c79cbd3125abdcb2bf75d01a968a4fd8833e412a45864453e1d20e9455dce8c6fba9f51204
SHA1 hash: c95ffa015198284a4bc23fc454a097a7a91f2ed2
MD5 hash: 8876382b1cbf3e14ae2d4cd90a94b797
humanhash: fillet-carolina-missouri-kitten
File name:Togethers.exe
Download: download sample
Signature Hades
File size:124'525'689 bytes
First seen:2026-09-12 06:44:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 3145728:ke4tdoYPtKInFj1iI+edz/gU3736zVq6w38N66gc4/:gToaKInFjeedz4Ur6Jqns6lc4/
TLSH T19E5833CA0315505FE486FBFB0D91E3BD2BEC2F616918C22B11F9DDEB706C9C6160196A
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 00c8c8eccdc86080 (1 x Hades)
Reporter devmihaylov
Tags:discord electron-builder exe Hades NSIS RAT stealer turkey


Avatar
devmihaylov
Hades, a licensed crimeware kit sold as a streaming application, combining browser and wallet theft, live Discord credential interception, a socket.io remote access channel and a desktop lockdown. Unsigned 32-bit NSIS installer, electron-builder output, 99.75 percent overlay, delivered from hxxps[://]www[.]togethers[.]tv/ and flagged by 1 of 61 vendors on VirusTotal when obtained. Steals fifteen Chromium profiles, Firefox through NSS and twelve desktop wallets, unwraps App-Bound Encryption v20 through the full CNG chain, intercepts Discord credentials live, carries a socket.io remote access channel with screen streaming and operator supplied HTML, and finishes with a desktop lockdown.

Intelligence


File Origin
# of uploads :
1
# of downloads :
382
Origin country :
BG BG
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-07 05:02:26 UTC
File Type:
PE (Exe)
Extracted files:
4419
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments