🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c706cda57bdedcba57008dba259b9c4e12564b7b4cc70c4b27fecd07ccaa8f51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HijackLoader


Vendor detections: 10


Intelligence 10 IOCs YARA 10 File information Comments

SHA256 hash: c706cda57bdedcba57008dba259b9c4e12564b7b4cc70c4b27fecd07ccaa8f51
SHA3-384 hash: 9d4bdd6c2a800c4149d04497dad53bcfd972327025b1a2999b7b3a4b7b287526418a24d21658e022d27b2a778a27328c
SHA1 hash: 3558294da51449fce9d596493a917f067865a798
MD5 hash: 9f987de2d727ed26dde4fc094f64bf8d
humanhash: jig-aspen-red-papa
File name:file
Download: download sample
Signature HijackLoader
File size:7'601'597 bytes
First seen:2026-09-13 08:00:20 UTC
Last seen:2026-09-13 20:15:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 20dd26497880c05caed9305b3c8b9109 (38 x HijackLoader, 31 x Adware.Auslogics, 7 x SnappyClient)
ssdeep 98304:Tw/6aTEaOZPpkIkh2XIpsmMTcsOBJbx8g7zljomuiSI2cpexJjI41Nd4d:U/jOhYpc4CgXlSRcmqgwd
TLSH T1D6763312D28340B7E5A1BF318C6B4E509F97F4F90CF0E55A9CB8D20E19B82E25979B74
TrID 72.8% (.EXE) Inno Setup installer (107240/4/30)
9.6% (.EXE) Win32 Executable Delphi generic (14182/79/4)
4.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.4% (.EXE) Win64 Executable (generic) (6522/11/2)
3.0% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b298acbab2ca7a72 (2'335 x GCleaner, 1'830 x Socks5Systemz, 67 x RedLineStealer)
Reporter Bitsight
Tags:D dropped-by-gcleaner EU0.file exe HIjackLoader


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
4
# of downloads :
159
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-13 08:04:27 UTC
Tags:
delphi hijackloader loader snappyclient rat stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-09-12T15:13:00Z UTC
Last seen:
2026-09-12T17:19:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader credential_access discovery installer loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Browser Information Discovery
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Detects HijackLoader (aka IDAT Loader)
Family: HijackLoader, IDAT loader, Ghostulse,
Unpacked files
SH256 hash:
c706cda57bdedcba57008dba259b9c4e12564b7b4cc70c4b27fecd07ccaa8f51
MD5 hash:
9f987de2d727ed26dde4fc094f64bf8d
SHA1 hash:
3558294da51449fce9d596493a917f067865a798
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
SH256 hash:
44b8e6a310564338968158a1ed88c8535dece20acb06c5e22d87953c261dfed0
MD5 hash:
9c8886759e736d3f27674e0fff63d40a
SHA1 hash:
ceff6a7b106c3262d9e8496d2ab319821b100541
SH256 hash:
8f0beb5863d190b7b2cfe7f506f3b721ab6b9e892337a133364f2ba710931b25
MD5 hash:
be3cc5717f5951662adb399d613f20cc
SHA1 hash:
f776bc4344ad59fbd6950d24d3aa6dddb3df215a
SH256 hash:
34bfb61619d324d1b7842f49360cdfeab74023b4293fe97cd962d24e9fa5b325
MD5 hash:
b14ea258f90bc51a2e97dcdb7d4e2efb
SHA1 hash:
18d46e7d25d5b793d594292c4f08a7e3dd551dbd
Malware family:
IDATLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HijackLoader

Executable exe c706cda57bdedcba57008dba259b9c4e12564b7b4cc70c4b27fecd07ccaa8f51

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments