MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b83df496537599eb055a897fa845b54003de4af855aa23f13c0e71224baae1e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkCloud


Vendor detections: 16


Intelligence 16 IOCs YARA 4 File information Comments

SHA256 hash: b83df496537599eb055a897fa845b54003de4af855aa23f13c0e71224baae1e1
SHA3-384 hash: dbe995297cab035e02a671a838a66baaf384497632363123656d3c793221beebbce3e2ef5dd640f7d68840df54543593
SHA1 hash: 1bb48b019749f49e14770b4f1494c4a8bbd0cfac
MD5 hash: 2001fb146b06bb10895faa3e974bdb3a
humanhash: princess-pluto-fanta-magnesium
File name:b83df496537599eb055a897fa845b54003de4af855aa23f13c0e71224baae1e1
Download: download sample
Signature DarkCloud
File size:1'261'056 bytes
First seen:2026-06-08 08:37:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'131 x AgentTesla, 20'159 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:N+AwBaaJmgVJ16u5cRLKxWvM/DRoGsV1+5mL6BWL4TS1:h3aJmgB6ucRLKccoGK1r6BWL44
Threatray 64 similar samples on MalwareBazaar
TLSH T1C5450224320ADF06D49F5A705570E3F9127B8E58AD11D3C38FFBBEABB4BA5452841293
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 4db292f2d88cb40b (32 x DarkTortilla, 27 x AgentTesla, 15 x RemcosRAT)
Reporter adrian__luca
Tags:DarkCloud exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
virus micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
loki packed snakekeylogger vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-24T23:23:00Z UTC
Last seen:
2026-06-10T06:09:00Z UTC
Hits:
~1000
Gathering data
Threat name:
ByteCode-MSIL.Trojan.SnakeKeylogger
Status:
Malicious
First seen:
2026-05-25 03:49:14 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
darkcloud
Score:
  10/10
Tags:
family:darkcloud discovery execution persistence stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: DarkCloud
Unpacked files
SH256 hash:
b83df496537599eb055a897fa845b54003de4af855aa23f13c0e71224baae1e1
MD5 hash:
2001fb146b06bb10895faa3e974bdb3a
SHA1 hash:
1bb48b019749f49e14770b4f1494c4a8bbd0cfac
SH256 hash:
aaef41ee9fc33ed143ce6cc29d5074d6067ce713e507e846bcf3cfd75fe1dea0
MD5 hash:
9852c1fc41e07275efbe2acedfcc5cb8
SHA1 hash:
30154b36e1a5ce73fd47d1db562b54b861d0cbde
Detections:
darkcloudstealer
SH256 hash:
da5dba78be66da201aa9adcf3e92a997c5744427c6c38f51917609c8850e4a4d
MD5 hash:
13caf94f8e7a8279fd3f0808cf4f8b20
SHA1 hash:
7541977f0b075a96bbb9d28a59241e871bd6d7b5
SH256 hash:
18adb948aa8cc24b367e81b2275264c230a9ce60fd3a32c8befc5f852dc9792b
MD5 hash:
91749dffb9df89f23401bf248c0cefdc
SHA1 hash:
b4b2969e3816a0a16dc06510c6778ff10d40a80b
SH256 hash:
3b75425895af4ae3186b36277553641e37ca1d620ae18d68e40d13351b54de6a
MD5 hash:
94d1531b52774dce52a89e33646d5b1d
SHA1 hash:
29bf887b025b97bd7a9e1e261852ba824234a625
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments