MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c35bb19ea8c10d9bdf35de591a4113ce2e26442a9e670784546c8b5209b53fed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HijackLoader


Vendor detections: 16


Intelligence 16 IOCs YARA 11 File information Comments

SHA256 hash: c35bb19ea8c10d9bdf35de591a4113ce2e26442a9e670784546c8b5209b53fed
SHA3-384 hash: c4a6551560ae6574aa7e72761564873564611bdff647d9a7b420c5411ec3e5501c767223fc6e2737a32fa94b5be102b3
SHA1 hash: 3acd79ebcbb76ab1975361bc11f432e9dd46faad
MD5 hash: 10ddfa8127cf1d32e3843de2506c4480
humanhash: fix-venus-burger-mobile
File name:DirtyGames.exe
Download: download sample
Signature HijackLoader
File size:11'997'176 bytes
First seen:2026-05-11 18:55:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b5a014d7eeb4c2042897567e1288a095 (24 x HijackLoader, 23 x GhostPulse, 14 x ValleyRAT)
ssdeep 196608:Jp3Ob744vdieLOihhv5+ZLZe3t4b+G5PoUc7AQ9tKiy1r0hgAXwO/FxZs1rF8l:Jp3844VYiDUQ3t4bvBq/n0AXwO/FPs1k
TLSH T118C63383E8E8C6F6E1FC577160BE241100FAA57B8186049A35C5AF4D0FFB54FA636A53
TrID 42.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
16.8% (.EXE) Win64 Executable (generic) (6522/11/2)
13.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon 70c0d0c09013b0e4 (1 x HijackLoader)
Reporter aachum
Tags:158-94-209-207 exe HIjackLoader


Avatar
iamaachum
C2: 158.94.209.207:57872

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
DirtyGames.exe
Verdict:
Malicious activity
Analysis date:
2026-04-19 06:24:17 UTC
Tags:
hijackloader loader delphi amsi-bypass

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
asyncrat autorun ramnit
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context fingerprint installer installer installer-heuristic microsoft_visual_cc overlay packed packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-03-24T01:59:00Z UTC
Last seen:
2026-05-12T02:45:00Z UTC
Hits:
~10
Result
Threat name:
HijackLoader
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Contains functionality to compare user and computer (likely to detect sandboxes)
Contains functionality to detect sleep reduction / modifications
Contains functionality to infect the boot sector
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Switches to a custom stack to bypass stack traces
Unusual module load detection (module proxying)
Yara detected HijackLoader
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1911855 Sample: DirtyGames.exe Startdate: 11/05/2026 Architecture: WINDOWS Score: 100 57 Found malware configuration 2->57 59 Malicious sample detected (through community Yara rule) 2->59 61 Multi AV Scanner detection for dropped file 2->61 63 4 other signatures 2->63 9 DirtyGames.exe 12 2->9         started        process3 file4 35 C:\Users\user\AppData\Local\...\vcomp140.dll, PE32 9->35 dropped 37 C:\Users\user\AppData\Local\...\KTEMain32.dll, PE32 9->37 dropped 39 C:\Users\user\...\Distributed-Analyzer.exe, PE32 9->39 dropped 12 Distributed-Analyzer.exe 7 9->12         started        process5 file6 41 C:\ProgramData\...\vcomp140.dll, PE32 12->41 dropped 43 C:\ProgramData\...\Distributed-Analyzer.exe, PE32 12->43 dropped 45 C:\...\Distributed-Analyzer.exe.manifest, XML 12->45 dropped 47 C:\ProgramData\...\KTEMain32.dll, PE32 12->47 dropped 75 Switches to a custom stack to bypass stack traces 12->75 16 Distributed-Analyzer.exe 7 12->16         started        signatures7 process8 file9 29 C:\Users\user\AppData\Roaming\...\Crisp.exe, PE32 16->29 dropped 31 C:\Users\user\AppData\Local\...\F42AD4E.tmp, PE32 16->31 dropped 33 C:\ProgramData\ThreaServer.exe, PE32 16->33 dropped 49 Found hidden mapped module (file has been removed from disk) 16->49 51 Maps a DLL or memory area into another process 16->51 53 Switches to a custom stack to bypass stack traces 16->53 55 Found direct / indirect Syscall (likely to bypass EDR) 16->55 20 ThreaServer.exe 16->20         started        23 Crisp.exe 16->23         started        signatures10 process11 signatures12 65 Contains functionality to infect the boot sector 20->65 67 Switches to a custom stack to bypass stack traces 20->67 69 Found direct / indirect Syscall (likely to bypass EDR) 20->69 73 2 other signatures 20->73 25 WerFault.exe 19 16 20->25         started        71 Unusual module load detection (module proxying) 23->71 27 WerFault.exe 23 16 23->27         started        process13
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout SFX 7z Win 32 Exe x86
Threat name:
Win32.Trojan.Penguish
Status:
Suspicious
First seen:
2026-03-24 07:10:55 UTC
File Type:
PE (Exe)
Extracted files:
507
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
tinyutility hijackloader
Similar samples:
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader discovery loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Family: HijackLoader, IDAT loader, Ghostulse,
Detects HijackLoader (aka IDAT Loader)
Unpacked files
SH256 hash:
c35bb19ea8c10d9bdf35de591a4113ce2e26442a9e670784546c8b5209b53fed
MD5 hash:
10ddfa8127cf1d32e3843de2506c4480
SHA1 hash:
3acd79ebcbb76ab1975361bc11f432e9dd46faad
SH256 hash:
05df93b01588c1ae1b4ff8ea4a614914eac6edad2f7eac5f90d46698f7b4fa12
MD5 hash:
24dea1231dd1dcdcbb002127826b5ce4
SHA1 hash:
1afb1e9ded1c62208ae7ce75a324e76591d6cbe8
SH256 hash:
dfe3ffff856785337703ccc9c5aebb626814d3882611b95eb152924666c74896
MD5 hash:
14203b65bf7da9d6605eda80ffad68a4
SHA1 hash:
9dfbb8092ab37564ecc879707cf38123b709cfa1
SH256 hash:
11bafe5e7c3bc685b15c2615e256d42c85daa56b0fe7448131e5ac5d85d0c841
MD5 hash:
1db1d6c93223bce277609f878e836886
SHA1 hash:
f31d0ef793f8efe353229178db6473a299bf362c
SH256 hash:
08a93ad91061aeda02121ae6a4fc9ec024f612e39626c615fd5f3765957608a4
MD5 hash:
2e259afb699d02eecfa0817e791e3324
SHA1 hash:
3873b36b6b1257dfa6543124383e932d553126a4
SH256 hash:
a6edb3fb6d21dd461da3767a7995034e208f7d6b08997f6cf7ee7b0ea833a8f0
MD5 hash:
cabb58bb5694f8b8269a73172c85b717
SHA1 hash:
9ed583c56385fed8e5e0757ddb2fdf025f96c807
SH256 hash:
68bee500e0080f21c003126e73b6d07804d23ac98b2376a8b76c26297d467abe
MD5 hash:
d4dae7149d6e4dab65ac554e55868e3b
SHA1 hash:
b3bea0a0a1f0a6f251bcf6a730a97acc933f269a
SH256 hash:
b2f679a42464fe3fb2fc0bb3bb6ff00cdefe1ddd7142dbf1da95cabf15d46a6c
MD5 hash:
11e566f644130820040756f727dff1fc
SHA1 hash:
f32415224bed909f43a7f755c2ae1d8ad8b55205
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HijackLoader

Executable exe c35bb19ea8c10d9bdf35de591a4113ce2e26442a9e670784546c8b5209b53fed

(this sample)

  
Delivery method
Distributed via web download

Comments