MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c496e8e8f7cc2e40c515c9dbd98ffce43861acaf504466f478ceaebf712214b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GCleaner


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: c496e8e8f7cc2e40c515c9dbd98ffce43861acaf504466f478ceaebf712214b8
SHA3-384 hash: cf84081aec29b69042bcf43036270ec24c90b3600aa9bfdb3e28f32c5d4acb61f2240770ba5899dc8d16152d80c5dbce
SHA1 hash: 3941abf37772bfdeefa1d8b8bc617f9e1ce4bd48
MD5 hash: 801e7911d8ef33ab7843bb638c0b5abc
humanhash: april-mirror-tennis-hamper
File name:setup_euone.bin
Download: download sample
Signature GCleaner
File size:1'232'896 bytes
First seen:2026-08-28 06:52:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'200 x AgentTesla, 20'366 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 24576:e2D0RPGsPf75YuCS/Z4x7YTMxjK4nRj1JUburjp5xMbVpdXEq:e2Ipeub4xUTMx2QRjQdXEq
TLSH T1CF45D0A067EA4F3DED9E3231503A6C1A53F7F8D76B31DB4E021250981B91F849E49BD2
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter aachum
Tags:dropped-by-OffLoader exe gcleaner


Avatar
iamaachum
http://91.92.242.236/setup?name=euone

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-28 06:58:05 UTC
Tags:
gcleaner loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Creating a file in the %temp% subdirectories
Launching a process
Deleting a recently created file
Creating a process from a recently created file
Searching for synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Launching the default Windows debugger (dwwin.exe)
Sending an HTTP GET request
Unauthorized injection to a recently created process
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expand lolbin masquerade msbuild obfuscated overlay packed packed
Result
Threat name:
GCleaner
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Found malware configuration
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sample uses process hollowing technique
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Silenttrinity Stager Msbuild Activity
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected GCleaner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1965109 Sample: setup_euone.bin.exe Startdate: 28/08/2026 Architecture: WINDOWS Score: 100 45 45.91.200.135 PODAONLV Netherlands 2->45 47 185.156.73.98 FDN3UA Netherlands 2->47 49 12 other IPs or domains 2->49 63 Found malware configuration 2->63 65 Antivirus detection for URL or domain 2->65 67 Multi AV Scanner detection for submitted file 2->67 69 7 other signatures 2->69 11 setup_euone.bin.exe 9 2->11         started        signatures3 process4 file5 41 C:\Users\user\AppData\Local\...\smezir.exe, PE32+ 11->41 dropped 79 Writes to foreign memory regions 11->79 81 Allocates memory in foreign processes 11->81 83 Sample uses process hollowing technique 11->83 85 Injects a PE file into a foreign processes 11->85 15 smezir.exe 2 11->15         started        18 MSBuild.exe 12 11->18         started        21 WerFault.exe 22 16 11->21         started        signatures6 process7 dnsIp8 95 Multi AV Scanner detection for dropped file 15->95 97 Modifies the context of a thread in another process (thread injection) 15->97 99 Injects a PE file into a foreign processes 15->99 23 MSBuild.exe 15->23         started        26 WerFault.exe 19 16 15->26         started        51 91.92.242.236, 49764, 80 OMEGATECH-ASSC Netherlands 18->51 53 drive.usercontent.google.com 142.251.215.65, 443, 49758 GOOGLE-GoogleLLCUS United States 18->53 signatures9 process10 signatures11 71 Injects code into the Windows Explorer (explorer.exe) 23->71 73 Allocates memory in foreign processes 23->73 75 Creates a thread in another existing process (thread injection) 23->75 77 2 other signatures 23->77 28 explorer.exe 26 4 23->28 injected process12 dnsIp13 61 systemformating.rest 172.67.165.83, 443, 49766, 49767 CLOUDFLARENET-CloudflareIncUS Canada 28->61 87 System process connects to network (likely due to code injection or exploit) 28->87 89 Tries to steal Mail credentials (via file / registry access) 28->89 91 Tries to harvest and steal ftp login credentials 28->91 93 2 other signatures 28->93 32 chrome.exe 28->32         started        signatures14 process15 dnsIp16 43 192.168.2.5, 138, 443, 49673 unknown unknown 32->43 35 chrome.exe 32->35         started        process17 dnsIp18 55 mobile-gtalk.l.google.com 142.250.101.188, 49793, 5228 GOOGLE-GoogleLLCUS United States 35->55 57 www.google.com 142.251.155.119, 443, 49774, 49780 GOOGLE-GoogleLLCUS United States 35->57 59 3 other IPs or domains 35->59 39 Chrome Cache Entry: 243, PDP-11 35->39 dropped file19
Verdict:
inconclusive
YARA:
11 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.29 SOS: 0.30 SOS: 0.31 Win 32 Exe x86
Result
Malware family:
gcleaner
Score:
  10/10
Tags:
family:gcleaner discovery loader
Behaviour
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Family: GCleaner
Malware Config
C2 Extraction:
185.156.73.98
45.91.200.135
Unpacked files
SH256 hash:
c496e8e8f7cc2e40c515c9dbd98ffce43861acaf504466f478ceaebf712214b8
MD5 hash:
801e7911d8ef33ab7843bb638c0b5abc
SHA1 hash:
3941abf37772bfdeefa1d8b8bc617f9e1ce4bd48
SH256 hash:
798e56c80a24ab20e6411aa11ce3b5c0419920b8bd5eff91424209b55abafc6d
MD5 hash:
e5342d032ba1f9224c24fc5dd7c23149
SHA1 hash:
e235944987266db71a4c1453701d92ca6dc5404b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GCleaner

Executable exe c496e8e8f7cc2e40c515c9dbd98ffce43861acaf504466f478ceaebf712214b8

(this sample)

  
Delivery method
Distributed via web download

Comments