🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c65081a6f97c0b087a7a2076d222745fd62fdce1eb0bfb0c628f07cb25cfae8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HijackLoader


Vendor detections: 12


Intelligence 12 IOCs YARA 3 File information Comments

SHA256 hash: c65081a6f97c0b087a7a2076d222745fd62fdce1eb0bfb0c628f07cb25cfae8a
SHA3-384 hash: 6d73b38ef8482bd06f9feccbac1bf3f4a9ee470efd8c832ae3ad98df8fb6d52a4ff15149d8357e855d7ad23b6a8224ba
SHA1 hash: 5cd6b1649d35a5cb3af5b447dd7ba41062df41ca
MD5 hash: 6efeedf66010c0abebb763204791dfe7
humanhash: earth-mississippi-stairway-violet
File name:file
Download: download sample
Signature HijackLoader
File size:8'298'669 bytes
First seen:2026-09-30 18:39:02 UTC
Last seen:2026-09-30 18:56:33 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 20dd26497880c05caed9305b3c8b9109 (39 x HijackLoader, 31 x Adware.Auslogics, 9 x SnappyClient)
ssdeep 196608:zl22MPgegWT2xwd4hWxzKAu/BGxeyYqNiIKp7x2zRY4jd:Z2VP0S2xwd4hCzKvBGxey3ipL2z645
TLSH T1CA8633837BDA41B0E1F25E320C96C84E7D5BB97214E0B85A6CB4C92D543AF898CB77D1
TrID 72.8% (.EXE) Inno Setup installer (107240/4/30)
9.6% (.EXE) Win32 Executable Delphi generic (14182/79/4)
4.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.4% (.EXE) Win64 Executable (generic) (6522/11/2)
3.0% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b298acbab2ca7a72 (2'335 x GCleaner, 1'831 x Socks5Systemz, 67 x RedLineStealer)
Reporter Bitsight
Tags:dropped-by-gcleaner exe HIjackLoader P UNIQPREM.file


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
2
# of downloads :
188
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-30 18:43:54 UTC
Tags:
delphi inno installer hijackloader loader auto-startup pecompact

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Deleting a recently created file
Creating a file in the %AppData% subdirectories
Unauthorized injection to a recently created process by context flags manipulation
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context adaptive-context anti-debug anti-vm crypto embarcadero_delphi expand expired-cert expired-cert fingerprint inno installer installer lolbin obfuscated packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-09-30T16:46:00Z UTC
Last seen:
2026-10-01T10:18:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader defense_evasion discovery installer loader privilege_escalation
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Executes dropped EXE
Loads dropped DLL
Detects HijackLoader (aka IDAT Loader)
Family: HijackLoader, IDAT loader, Ghostulse,
Unpacked files
SH256 hash:
c65081a6f97c0b087a7a2076d222745fd62fdce1eb0bfb0c628f07cb25cfae8a
MD5 hash:
6efeedf66010c0abebb763204791dfe7
SHA1 hash:
5cd6b1649d35a5cb3af5b447dd7ba41062df41ca
SH256 hash:
d6410ca2c1da978fe63298d59dd85a32ccbff422c12bbfaef478fb304e998558
MD5 hash:
733553671b79bc45e758cd85b8c63ca3
SHA1 hash:
38c4087720e1b5d7ba08efb5f816da0bbc16bb03
SH256 hash:
2edbe3ccd2e40af827b176f914dcfdb015f08ca1043b0d04e0d6fc838aa5a940
MD5 hash:
bead1d696b3aea8130ea1eb355e3e2d2
SHA1 hash:
a02b7c00a7b8a4366b8135a8da3fdfd83c6afccd
SH256 hash:
7acc7eeff989c4b0b48c4d5c909039b4e7c1fc0cf5f55d528e61128911fd1332
MD5 hash:
c3177e645b3748136ce1d54ff148e644
SHA1 hash:
b6761fed8cd945b67c3ca394223907add85e3866
SH256 hash:
5bf439f4d238bf16d9d2b3ed2623c663ac03ac1f5f994b56ef966b19e4eeccdc
MD5 hash:
e850fae197fdb5c648245b28f752f868
SHA1 hash:
e18df5569fee7f14a3c11ab3937dfac1e89f9ecd
SH256 hash:
d3432d1edfe2a623cb042ffb93554c40ff61ec92df4299c40f6d4adcb6f7e5ff
MD5 hash:
6d48331f1242d5023259ea692a8c04db
SHA1 hash:
e6b106f7ff17e51e3a75b341627715b98688e7f7
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
SH256 hash:
44b8e6a310564338968158a1ed88c8535dece20acb06c5e22d87953c261dfed0
MD5 hash:
9c8886759e736d3f27674e0fff63d40a
SHA1 hash:
ceff6a7b106c3262d9e8496d2ab319821b100541
SH256 hash:
8f0beb5863d190b7b2cfe7f506f3b721ab6b9e892337a133364f2ba710931b25
MD5 hash:
be3cc5717f5951662adb399d613f20cc
SHA1 hash:
f776bc4344ad59fbd6950d24d3aa6dddb3df215a
SH256 hash:
1d9d43bbac357d5aa3381bab28ebf80c8f9e0156d54a7ea142751b6bf1ca244f
MD5 hash:
e88d361229a5e3629ca4d5ee58315b37
SHA1 hash:
22cba86907e351e9b1178240657c4e3fdfdbe628
SH256 hash:
267801a83a4cb1110e17a259c52db3af3c8bc9e11c29b9f7d85e04a95b8b30e0
MD5 hash:
6a5f85f4d0b0242553b461d6b57cc744
SHA1 hash:
6dd4a4c329a13fae677bf44635c912ec9e80e559
SH256 hash:
a6edb3fb6d21dd461da3767a7995034e208f7d6b08997f6cf7ee7b0ea833a8f0
MD5 hash:
cabb58bb5694f8b8269a73172c85b717
SHA1 hash:
9ed583c56385fed8e5e0757ddb2fdf025f96c807
SH256 hash:
68bee500e0080f21c003126e73b6d07804d23ac98b2376a8b76c26297d467abe
MD5 hash:
d4dae7149d6e4dab65ac554e55868e3b
SHA1 hash:
b3bea0a0a1f0a6f251bcf6a730a97acc933f269a
SH256 hash:
32b47e15d95dd190890ce3bf4d35661b0ea4a56dcaf04b505bec5db10f0cecd4
MD5 hash:
65b8544367b87265eedaa1a6e4295ce8
SHA1 hash:
dd28b8a4da7eebd95011dec371e178031f04b204
Malware family:
SnappyClient
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HijackLoader

Executable exe c65081a6f97c0b087a7a2076d222745fd62fdce1eb0bfb0c628f07cb25cfae8a

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments