MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c05581c54fb2e63ab1b6d0c8957d24fbcbc0e094339bc02838b50b3f72dddeff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PythonStealer


Vendor detections: 9


Intelligence 9 IOCs YARA 7 File information Comments

SHA256 hash: c05581c54fb2e63ab1b6d0c8957d24fbcbc0e094339bc02838b50b3f72dddeff
SHA3-384 hash: 23d4d543089a58d9ba6823ab6b2f09d3576bbdb4c6a4db061273a3f6464f449a28f8d0ba7fca3beb2255f52136ccc7e9
SHA1 hash: c4923d8832f29f2d60a768e62e60fef0f0005e8c
MD5 hash: 9188e2a2bc5f9e23dfb62cff8589ae64
humanhash: virginia-cola-enemy-earth
File name:file
Download: download sample
Signature PythonStealer
File size:18'318'848 bytes
First seen:2026-07-30 18:42:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 8b363bc238af20b3aebe4e1b7d7f2bd0 (1 x PythonStealer)
ssdeep 393216:lXqDC8y9St2vIeNGGoNcRxRK0W4Dxqz1KdhWUe0P:slHC0vN6Rl2sv
TLSH T1B307333A91142678FB1BE138238795D03109BAE213BA54F35A71D1341EBB8FD7874A7E
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Bitsight
Tags:d52f85 dropped-by-amadey exe PythonStealer


Avatar
Bitsight
url: http://62.60.226.140/files/7997280925/yXhtFdg.exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
DNS request
Connection attempt
Sending a custom TCP request
Creating a file
Deleting a recently created file
Running batch commands
Creating a process with a hidden window
Launching a process
Loading a suspicious library
Using the Windows Management Instrumentation requests
Forced system process termination
Creating a window
Searching for the window
Reading critical registry keys
Changing a file
Launching a tool to kill processes
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 expand lolbin nuitka packed packed reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-30T17:02:00Z UTC
Last seen:
2026-08-01T00:51:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
blankgrabber
Score:
  10/10
Tags:
family:blankgrabber defense_evasion discovery execution spyware stealer
Behaviour
Gathers system information
Kills process with taskkill
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
Checks installed software on the system
Looks up external IP address via web service
Loads dropped DLL
Reads user/profile data of web browsers
A stealer written in Python and packaged with Pyinstaller
Family: blankgrabber
Unpacked files
SH256 hash:
c05581c54fb2e63ab1b6d0c8957d24fbcbc0e094339bc02838b50b3f72dddeff
MD5 hash:
9188e2a2bc5f9e23dfb62cff8589ae64
SHA1 hash:
c4923d8832f29f2d60a768e62e60fef0f0005e8c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PythonStealer

Executable exe c05581c54fb2e63ab1b6d0c8957d24fbcbc0e094339bc02838b50b3f72dddeff

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

Comments