MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c5a3d94cb6b4be539b68401e2fbd8008740d230109ee13a5b3b863f8e2d935c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 8


Intelligence 8 IOCs YARA 21 File information Comments

SHA256 hash: c5a3d94cb6b4be539b68401e2fbd8008740d230109ee13a5b3b863f8e2d935c1
SHA3-384 hash: 0cc74207ca9537a68f2e68bc35713ac1357791b8d112556b57e929884a8f04f368eea3d3e88288a6bc9ced5cad58c767
SHA1 hash: df2b580f61876f7b2b7f1fea312eafb81ae3b406
MD5 hash: bfbbf30418735fa202dd952435235c23
humanhash: burger-quiet-artist-hotel
File name:package
Download: download sample
Signature KongTuke
File size:16'871'997 bytes
First seen:2026-07-27 14:11:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:uIPdqdV/tYiXENQ14sXt10ANqkRZd6BVp81mJw1fsFi13:XqbSiSQ1JXLN/r6fDJ+kc13
TLSH T13B07339FD4110484BA3CEC6920C6C7D5CC136F1485BB6934AD0B9839676BBE6FE943AC
Magika zip
Reporter monitorsg
Tags:Kongtuke zip


Avatar
monitorsg
hXXps://bauabach[.]lol/zcfo2l6c.js (ClickFucker) --> hXXps://bauabach[.]lol/api/v1/session (token) --> hXXps://bauabach[.]lol/api/v1/verify (gateway) --> hXXps://bauabach[.]lol/api/v1/status (clipboard) --> hXXps://globalupdate6711[.]com/update/package (tar)

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
US US
File Archive Information

This file archive contains 22 file(s), sorted by their relevance:

File name:xul.dll
File size:8'611'840 bytes
SHA256 hash: e2132030c24169e9e615d1dc9f9e2c88f1c3036fdda5e0e6de8a46fe20c64fd9
MD5 hash: e68230b76b25974350f96d0b21cc61d4
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.manifest
File size:240 bytes
SHA256 hash: 23680bbba9edbbfab98e27f9bd676b031da3b20adfe909ce86c9ecc1b8bb80d1
MD5 hash: 5d5e62ad6d1023592406fe3ea1f0ea75
MIME type:text/xml
Signature KongTuke
File name:vcruntime140_1.dll
File size:47'264 bytes
SHA256 hash: e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
MD5 hash: 03b43160d21c08de07a79d0a1c5ee81d
MIME type:application/x-dosexec
Signature KongTuke
File name:AccessibleMarshal.dll
File size:939'520 bytes
SHA256 hash: 602c6c390322a95cb1b472d26482d65a3abf13161d64a2c4e3b628a79031f2a3
MD5 hash: b62acdc0ff460fac2434e3e83068329b
MIME type:application/x-dosexec
Signature KongTuke
File name:gkcodecs.dll
File size:939'520 bytes
SHA256 hash: ea60594234bcd793c56001ecb7c27acdef13c61949c364afad365cefc0fa136e
MD5 hash: 6834da4f663732bd1feed1dd087f1567
MIME type:application/x-dosexec
Signature KongTuke
File name:mozglue.dll
File size:850'944 bytes
SHA256 hash: 545688375f250dadc12b703eab466335aba2498df634b25cc9a4372b5292f2ff
MD5 hash: 8a2a3af77de1fd848d8645f35bb535ea
MIME type:application/x-dosexec
Signature KongTuke
File name:plugin-container.exe
File size:144'512 bytes
SHA256 hash: b2f2b9a3a712125a06b303344b7a0dc57f91ee6f1749c731ca2260931dbe24e9
MD5 hash: 65729157b053d4d373595f7a53126298
MIME type:application/x-dosexec
Signature KongTuke
File name:wmfclearkey.dll
File size:891'392 bytes
SHA256 hash: 79c2bd54ba4aeee47f1bc921720afb69cf99eb69f7629822e3d011e7a689156f
MD5 hash: 8a78737ebd300af998720a2cbdb3cb40
MIME type:application/x-dosexec
Signature KongTuke
File name:freebl3.dll
File size:939'520 bytes
SHA256 hash: 935b491407fd8ece0fd092b549a93958ecaa3aadbe30fee4927f34d3c9935eb3
MD5 hash: 7a3f748915803877b442174414af6428
MIME type:application/x-dosexec
Signature KongTuke
File name:mozinference.dll
File size:939'520 bytes
SHA256 hash: 03bd6abac123fe2d874ed23e88558301b784b877dc970b9a9b331d8611471612
MD5 hash: 198046238448ef925bfd8682321c08e5
MIME type:application/x-dosexec
Signature KongTuke
File name:vcruntime140.dll
File size:123'472 bytes
SHA256 hash: 184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
MD5 hash: 0d35c5e99871b4f02c490b9fd9dace34
MIME type:application/x-dosexec
Signature KongTuke
File name:nss3.dll
File size:940'032 bytes
SHA256 hash: a020eb6de27d7a9852a583026916e42934cc5f35084f8400fd94a6a3e7aab6c2
MD5 hash: cdd36cb3242c5774756d2422e6d1c665
MIME type:application/x-dosexec
Signature KongTuke
File name:libEGL.dll
File size:3'081'728 bytes
SHA256 hash: 8efbab8699cfb1fe6262c600baa86d067f1d150630c40dac856429e4da1fcd51
MD5 hash: 788aa1c575353fd4ee8159bc0619fa55
MIME type:application/x-dosexec
Signature KongTuke
File name:libGLESv2.dll
File size:3'091'968 bytes
SHA256 hash: a01ef28c7f06faaeacea710591dbada4dd8893bbcc9c01d453345d0ad9c5e65b
MD5 hash: 674f68ccca6db3bdd61c2c54482c3da0
MIME type:application/x-dosexec
Signature KongTuke
File name:nssutil3.dll
File size:6'480'896 bytes
SHA256 hash: 1cdb502652389e9ffb2880ad096b8690741acd6e962e2320359c5e45ca3ae495
MD5 hash: 764f0e16479e48049439ea198ede0500
MIME type:application/x-dosexec
Signature KongTuke
File name:notificationserver.dll
File size:838'144 bytes
SHA256 hash: dece831bea93531324aa00d33c188f69a6a10132c38f00ded62c1bae357487b9
MD5 hash: 99d2c07a00973d8b3fc850276f8e51d3
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavcodec.dll
File size:1'102'336 bytes
SHA256 hash: acb3604d61b2f5262801ec7bd837541ebf8d63ab8c267271366974834cc6bbaf
MD5 hash: e50ed1d3250099df83e3ba8105790ffc
MIME type:application/x-dosexec
Signature KongTuke
File name:mozavutil.dll
File size:3'076'608 bytes
SHA256 hash: 4679cfa41c84deba3042607ef24e934230f35cd89068dcdd984d708aff11beb1
MD5 hash: 8ad14d1518432316f224eb6b16446516
MIME type:application/x-dosexec
Signature KongTuke
File name:msvcp140.dll
File size:553'552 bytes
SHA256 hash: def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
MD5 hash: 4e3fa9bd90ef020c14359639dc19312b
MIME type:application/x-dosexec
Signature KongTuke
File name:mozwer.dll
File size:939'520 bytes
SHA256 hash: a9aa9858bae1224a431240b4b3b3455751701af29491c369782811b74b086806
MD5 hash: 1ebdc65090f278c67be32543829ec11a
MIME type:application/x-dosexec
Signature KongTuke
File name:lgpllibs.dll
File size:940'032 bytes
SHA256 hash: 21547e4c3fc767671906a06016bb80f14b5ea6a43134347886f2130401531a02
MD5 hash: 6117211291d28383c9a74a4807c56872
MIME type:application/x-dosexec
Signature KongTuke
File name:softokn3.dll
File size:940'544 bytes
SHA256 hash: 1601612ef34e7199e0fc73feaa95870ddd25a67234aa1957c007740106e679e0
MD5 hash: e599bda5bf96c05bce1cf53b9f41127d
MIME type:application/x-dosexec
Signature KongTuke
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.Wacatac
Status:
Malicious
First seen:
2026-07-27 14:12:48 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:remus_stealer defense_evasion discovery execution spyware stealer
Malware Config
C2 Extraction:
http://easeal.top:5291
http://zelpx.garden:9895
http://tzpx.courses:4437
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

zip c5a3d94cb6b4be539b68401e2fbd8008740d230109ee13a5b3b863f8e2d935c1

(this sample)

  
Delivery method
Distributed via web download

Comments