MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7e18d6227ed641061b9e7a24ddfe3002f4c449b6107a5ff8a3976ef4e20c05a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 12 File information Comments

SHA256 hash: b7e18d6227ed641061b9e7a24ddfe3002f4c449b6107a5ff8a3976ef4e20c05a
SHA3-384 hash: b5acda549fc3b84b5b4acc287aeba391a6c839b639ff30743395938c9ac6bed97588515b079bab35a8692383f153b941
SHA1 hash: f829203051e703d069c9d15d5cd8e341a16cd137
MD5 hash: 015887045facca4a7cc4713a5479f5c7
humanhash: april-vermont-magnesium-thirteen
File name:libvlccore.dll
Download: download sample
File size:6'731'068 bytes
First seen:2026-05-08 08:11:48 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash fad4cfe684646d5a98919bdc92bd72bc
ssdeep 49152:yyzhJB0nQdQjMiXKxGsQ90ubIshBnc/BiTfJH15oc8jnaEQRox1fZjIsi5FK2mpA:wnQmjMiXCQ90ubIshBnc/Bu/ocgj4n
Threatray 1 similar samples on MalwareBazaar
TLSH T133665B01E506C075E54A37B02936E7EAE2687E2DF7634AD3EACC3E546D329C21131AD7
TrID 34.6% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
25.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
13.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
5.4% (.EXE) Win64 Executable (generic) (6522/11/2)
Magika pebin
Reporter dght_432
Tags:dll dllHijack stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
225
Origin country :
n/a
Vendor Threat Intelligence
No detections
Gathering data
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug evasive invalid-signature microsoft_visual_cc overlay packed signed
Verdict:
Malicious
File Type:
dll x32
First seen:
2026-04-28T09:51:00Z UTC
Last seen:
2026-05-09T22:37:00Z UTC
Hits:
~100
Detections:
Trojan.Win32.Agent.xcdusf
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE Memory-Mapped (Dump)
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-28 01:02:14 UTC
File Type:
PE (Dll)
Extracted files:
5
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
unc_loader_053
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Unpacked files
SH256 hash:
b7e18d6227ed641061b9e7a24ddfe3002f4c449b6107a5ff8a3976ef4e20c05a
MD5 hash:
015887045facca4a7cc4713a5479f5c7
SHA1 hash:
f829203051e703d069c9d15d5cd8e341a16cd137
SH256 hash:
b709c8f1833aff3dfee465e2e16dad5c6cc6d6fce58e58f04b1ea6cacb3c9d9c
MD5 hash:
fe46bef854d2039806736bfb3f01fbc9
SHA1 hash:
6276913ec33c3aae430ba203b6f8ec1c291a0ef4
SH256 hash:
e89c01d178bfbdce303368a911a86c6f5bdb232409b60a89d1cadac004b7fb50
MD5 hash:
653489aa9c13cd7d9db23c94e50352c6
SHA1 hash:
8f954c34e0be408950a952853cf5540d649f2ed6
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments