🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be33857b248abf63e9a1883f5369ee14f34c274e2ad82908ffde00477cc4cd2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: be33857b248abf63e9a1883f5369ee14f34c274e2ad82908ffde00477cc4cd2a
SHA3-384 hash: b12a01ae84dad78628f852cf7e4e8d034615b0e6f4e0b7e024be75ea25ec664cb6bd8b6872c929b909ee60531ec20e16
SHA1 hash: d39952cd252601f4f12876d189ca0718fe6c9285
MD5 hash: 2012d1a323722a43d8c4c7f1e3dd650c
humanhash: alabama-enemy-angel-echo
File name:Important_Noticeលិខិតជូនដំណឹងសំខាន់2026_07_08_PDF.rar
Download: download sample
Signature Gh0stRAT
File size:17'702'059 bytes
First seen:2026-07-08 11:42:34 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 393216:JMBl/oqHkU1YI3T/nPsxwL60vjgQtetsHFqKbBYslshNuimUoztgp:JMb/1H3TnPBtetmFqKbqsYNIUIS
TLSH T10B0733335DAEF4645FB6E605DBC82608BAF262E73853B566931CC4F2D74985760E32C0
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:Gh0stRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:II-2 (2).exe
File size:18'175'281 bytes
SHA256 hash: 2df5ef90f375164ffac7baffce2cfae57fe69488c972e55435097420110c89a3
MD5 hash: 0e17d7116bfd4da8199f6aa90c547aca
MIME type:application/x-dosexec
Signature Gh0stRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
dropper virus spawn
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context embarcadero_delphi evasive fingerprint inno installer installer installer-heuristic packed reconnaissance
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-08T03:20:00Z UTC
Last seen:
2026-07-10T05:14:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-07-08 08:33:34 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments