🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4819763eefcd07e7d3a1e3b124e8b728f03449633d06ba9fa2f5cc85402527f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RustyStealer


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: c4819763eefcd07e7d3a1e3b124e8b728f03449633d06ba9fa2f5cc85402527f
SHA3-384 hash: 7980f638e46fda31cdd12a6dd3970f14324d70c0c241f50a81eb9d7dbac0cb8caa2354a995db9378adbeff2b294f991d
SHA1 hash: c0707b7b24f3db1a5e8647ac51cd52575601397a
MD5 hash: 6fc6908ab23848fc7cace65a3934f629
humanhash: august-sink-magazine-edward
File name:T-202692201421.iso
Download: download sample
Signature RustyStealer
File size:2'060'288 bytes
First seen:2026-09-23 09:22:37 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:Cekc3+Il3xu8KwGqbEdUXlG9RsoLu9jC31fhQAf76hOEptlByN+:CekX63fKqoGOK3
TLSH T1D5950273E5E32765F6E3687D91AB7E282A6FD3300F260853152C16C2435E2D01BFA65B
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter smica83
Tags:iso RustyStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:T-202692201421.exe
File size:212'496 bytes
SHA256 hash: f5f75473ebc98ad8e23f57fdb77393477027accf2581da809b74c122de9f0931
MD5 hash: 04ad35ccce1b87a70680b12f5f86e29d
MIME type:application/x-dosexec
Signature RustyStealer
File name:resources.dat
File size:1'785'745 bytes
SHA256 hash: ade656473d033a0cf95fb98b737726fb40bd1372cd68f20220e2c6bc7d271369
MD5 hash: 4a87bf790eb6e0527fb2d29cb6f5fda2
MIME type:application/octet-stream
Signature RustyStealer
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm evasive microsoft_visual_cc overlay packed packed revoked-cert signed
Verdict:
Malicious
File Type:
iso
First seen:
2026-09-23T06:39:00Z UTC
Last seen:
2026-09-23T07:13:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Executable ISO9660 Image PDB Path PE (Portable Executable) PE File Layout
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-09-22 12:02:01 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery evasion execution persistence revoked_codesign trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Windows security modification
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender Real-time Protection settings
Modifies Windows Defender TamperProtection settings
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Rustyloader_mem_loose
Author:James_inthe_box
Description:Corroded buerloader
Reference:https://app.any.run/tasks/83064edd-c7eb-4558-85e8-621db72b2a24
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments