🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b72a6b976bee7d287187cee75bab7ea826964d2f16f2cd03a7295bdbe9cfbab1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 6 File information Comments

SHA256 hash: b72a6b976bee7d287187cee75bab7ea826964d2f16f2cd03a7295bdbe9cfbab1
SHA3-384 hash: 4a5f8356c10ca4046fe12432bb6367471e97064004b3ca79dea0994e2454dcfadfa818c3dae271e03dff739de534fa33
SHA1 hash: b96327b4130559586687df7719473baf54f7cd12
MD5 hash: a4ed535364077a23998366fd579c80f7
humanhash: pluto-wolfram-wisconsin-cat
File name:b72a6b976bee7d287187cee75bab7ea826964d2f16f2cd03a7295bdbe9cfbab1.exe
Download: download sample
File size:5'442'460 bytes
First seen:2026-10-02 21:18:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/vnd.microsoft.portable-executable
imphash 884310b1928934402ea6fec1dbd3cf5e (3'725 x GCleaner, 3'609 x Socks5Systemz, 262 x RaccoonStealer)
ssdeep 98304:MJgoz/dv5BLft5YR6r/47mkt/bKiELPpLI7EM9on6XyQVXIKH8:ogMVv5BLftTSt/2BLI4Aon6Ab
TLSH T1C446339674F37C71C0C2AE788C3CD35286A87E762720539D35C9582C9B7ABDA834C09B
TrID 76.2% (.EXE) Inno Setup installer (107240/4/30)
10.0% (.EXE) Win32 Executable Delphi generic (14182/79/4)
4.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.4% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon b298acbab2ca7a72 (2'335 x GCleaner, 1'831 x Socks5Systemz, 67 x RecordBreaker)
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
206
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Suspicious activity
Analysis date:
2026-10-02 21:34:24 UTC
Tags:
inno installer delphi

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
active-directory adaptive-context anti-debug borland_delphi fingerprint inno installer installer keylogger macros packed reconnaissance smb
Verdict:
Suspicious
Labled as:
Suspicious:InstallCore.XB.hwzw
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
8 / 100
Behaviour
Behavior Graph:
n/a
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Unpacked files
SH256 hash:
b72a6b976bee7d287187cee75bab7ea826964d2f16f2cd03a7295bdbe9cfbab1
MD5 hash:
a4ed535364077a23998366fd579c80f7
SHA1 hash:
b96327b4130559586687df7719473baf54f7cd12
SH256 hash:
83edbbdda5738915a281565f51ccbd5a1cb820e1418e2fcef1139bc1a8659ded
MD5 hash:
46ccfbcf84f7a0280a53e1db2e515c2a
SHA1 hash:
ecd55cef61f1ed0d748b5ee8b9d3ccbda047283c
SH256 hash:
b20a8d88c550981137ed831f2015f5f11517aeb649c29642d9d61dea5ebc37d1
MD5 hash:
526426126ae5d326d0a24706c77d8c5c
SHA1 hash:
68baec323767c122f74a269d3aa6d49eb26903db
SH256 hash:
44b8e6a310564338968158a1ed88c8535dece20acb06c5e22d87953c261dfed0
MD5 hash:
9c8886759e736d3f27674e0fff63d40a
SHA1 hash:
ceff6a7b106c3262d9e8496d2ab319821b100541
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:ScanStringsInsocks5systemz
Author:Byambaa@pubcert.mn
Description:Scans presence of the found strings using the in-house brute force method
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:WIN_Malware_Unknown_ForgeAuto_6422f546_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_b550d7b4_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_f5d58a9e_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe b72a6b976bee7d287187cee75bab7ea826964d2f16f2cd03a7295bdbe9cfbab1

(this sample)

  
Delivery method
Distributed via web download

Comments