MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bcc547826973f84cf542f9073d79054a32b6d2eb99170e809461ed5da877fbe2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 16 File information Comments

SHA256 hash: bcc547826973f84cf542f9073d79054a32b6d2eb99170e809461ed5da877fbe2
SHA3-384 hash: 86f2ff19c182b44bc5b0379f8d9a87c318c51003ae9a24bb8edb99f73fb1945bc11b85710feab24a1e9e12f5663d1c2d
SHA1 hash: 3446e02ccabaa7729aa8c2c68a889740b70e27f3
MD5 hash: 5c3dac1fbb4cefa79533b28b0b24accd
humanhash: batman-fanta-rugby-march
File name:Setup.exe
Download: download sample
File size:74'448'896 bytes
First seen:2026-08-16 02:02:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4cea7ae85c87ddc7295d39ff9cda31d1 (103 x LummaStealer, 85 x RedLineStealer, 62 x Rhadamanthys)
ssdeep 49152:rMz0Md4S4UAv9M4k5582WqcCY9tOOESoYse8UNGnfaUhT/V:O0MWCAG4kj82Wds7SkmGhhT/V
TLSH T146F7234157E50096D074BBF8D9A545A25A31BD421BFA5B8F22B4F90E2F722E3EC7130B
TrID 45.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
18.0% (.EXE) Win64 Executable (generic) (6522/11/2)
13.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.6% (.ICL) Windows Icons Library (generic) (2059/9)
5.6% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon 0f0f4df0f00d170f
Reporter aachum
Tags:45-115-27-4 AsgardProtector exe SunWukong VorishkaStealer


Avatar
iamaachum
https://mvnerui.co/ => https://www.mediafire.com/file/fb33otoer2xydv2/SETUP_ARCHIVE_(KEY_2345).zip/file

VorishkaStealer C2: 45.115.27.4:12345

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-16 02:11:10 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Launching a process
Creating a process with a hidden window
Creating a process from a recently created file
Creating a window
DNS request
Deleting a recently created file
Creating a file
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Reading critical registry keys
Using the Windows Management Instrumentation requests
Unauthorized injection to a recently created process by context flags manipulation
Stealing user critical data
Forced shutdown of a browser
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug autoit CAB expired-cert fingerprint installer installer installer-heuristic keylogger lolbin microsoft_visual_cc reconnaissance rundll32 runonce sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-15T19:53:00Z UTC
Last seen:
2026-08-15T22:45:00Z UTC
Hits:
~100
Result
Threat name:
EtherHiding, ZigClipper
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Contains functionality to inject code into remote processes
Detected PE file pumping (to bypass AV & sandboxing)
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Uses ipconfig to lookup or modify the Windows network settings
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Writes to foreign memory regions
Yara detected EtherHiding
Yara detected ZigClipper
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1958592 Sample: Setup.exe Startdate: 16/08/2026 Architecture: WINDOWS Score: 100 63 bsc.blockrazor.xyz 2->63 65 vghGdHNGWCHFWqlMSCAQK.vghGdHNGWCHFWqlMSCAQK 2->65 67 4 other IPs or domains 2->67 97 Suricata IDS alerts for network traffic 2->97 99 Found malware configuration 2->99 101 Antivirus detection for URL or domain 2->101 105 11 other signatures 2->105 10 Setup.exe 4 2->10         started        14 msedge.exe 29 543 2->14         started        signatures3 103 Performs DNS queries to domains with low reputation 63->103 process4 dnsIp5 55 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32+ 10->55 dropped 113 Uses ipconfig to lookup or modify the Windows network settings 10->113 17 AutoIt3.exe 10->17         started        20 ipconfig.exe 1 10->20         started        85 192.168.2.5, 12345, 138, 443 unknown unknown 14->85 87 239.255.255.250 unknown ZZ 14->87 57 C:\Users\user\AppData\Local\...\Web Data, SQLite 14->57 dropped 59 C:\Users\user\AppData\Local\Microsoft\...\LOG, ASCII 14->59 dropped 22 msedge.exe 14->22         started        25 msedge.exe 14->25         started        27 msedge.exe 14->27         started        file6 signatures7 process8 dnsIp9 89 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 17->89 91 Suspicious powershell command line found 17->91 93 Found many strings related to Crypto-Wallets (likely being stolen) 17->93 95 6 other signatures 17->95 29 AutoIt3.exe 122 102 17->29         started        34 conhost.exe 20->34         started        69 13.89.179.12, 443, 49799 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 22->69 71 150.171.109.149, 443, 49788 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 22->71 73 23 other IPs or domains 22->73 signatures10 process11 dnsIp12 79 45.115.27.4, 12345, 49810 NETGATE-SOLUTION-ASRO Germany 29->79 81 91.92.47.8, 49811, 80 CYBERZONEHUBPA United Kingdom 29->81 83 api.ipify.org 104.26.13.205, 443, 49757 CLOUDFLARENET-CloudflareIncUS Canada 29->83 61 C:\Users\user\...\2026-08-16 00.22.11.exe, PE32+ 29->61 dropped 115 Suspicious powershell command line found 29->115 117 Tries to harvest and steal browser information (history, passwords, etc) 29->117 119 Writes to foreign memory regions 29->119 121 4 other signatures 29->121 36 powershell.exe 29->36         started        40 2026-08-16 00.22.11.exe 29->40         started        43 chrome.exe 29->43         started        45 msedge.exe 11 29->45         started        file13 signatures14 process15 dnsIp16 53 C:\Users\user\AppData\Local\...\result.zip, Zip 36->53 dropped 107 Found many strings related to Crypto-Wallets (likely being stolen) 36->107 109 Loading BitLocker PowerShell Module 36->109 47 conhost.exe 36->47         started        75 celebration-internet.cc 104.21.4.73, 443, 49813 CLOUDFLARENET-CloudflareIncUS Canada 40->75 77 bsc.blockrazor.xyz 104.26.8.35, 443, 49812 CLOUDFLARENET-CloudflareIncUS Canada 40->77 111 Found direct / indirect Syscall (likely to bypass EDR) 40->111 49 WerFault.exe 3 16 43->49         started        51 WerFault.exe 16 43->51         started        file17 signatures18 process19
Gathering data
Threat name:
Win64.Malware.Generic
Status:
Suspicious
First seen:
2026-08-16 01:33:58 UTC
AV detection:
7 of 38 (18.42%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution spyware stealer
Behaviour
Gathers network information
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Suspicious use of SetThreadContext
Checks installed software on the system
Looks up external IP address via web service
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BunnyLoader
Author:indest
Description:generic crypto/card stealer rule
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe bcc547826973f84cf542f9073d79054a32b6d2eb99170e809461ed5da877fbe2

(this sample)

  
Delivery method
Distributed via web download

Comments