🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c73b8cb9c3a35b29d83749da7530033f036cc1cbd7b52d442f35b39e4b1cbae9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 15 File information Comments

SHA256 hash: c73b8cb9c3a35b29d83749da7530033f036cc1cbd7b52d442f35b39e4b1cbae9
SHA3-384 hash: be1d5e108e533efcf153c65061d8b42df4a9b3f62e1192e4d38b8b89d6fc1857ea532d8153f9919e19aac37dda09c338
SHA1 hash: c7fbfd2621121c8e655b25bea4f99711aa6cf70b
MD5 hash: 71947d95ac64782101ba0ccf8d6bea36
humanhash: tennessee-angel-jupiter-diet
File name:c73b8cb9c3a35b29d83749da7530033f036cc1cbd7b52d442f35b39e4b1cbae9.bin
Download: download sample
File size:4'659'200 bytes
First seen:2026-09-22 01:39:36 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 98304:VYTwTwTtTRTuT2gHFhhoEITUTHdfgdiPoT:VIglhyETdfgdiP
TLSH T1F2266C102A47C809D16D0230D03CB2FB01766E04D77A95FF6C9A7E6AF471B4E4AAE6D7
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 0c6c24b5934b634c
Reporter whack_sh
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
160
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Suspicious activity
Analysis date:
2026-09-22 01:40:06 UTC
Tags:
auto-reg

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching a process
Сreating synchronization primitives
Creating a window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-vm base64 corrupted evasive fingerprint lolbin masquerade obfuscated overlay reconnaissance reconnaissance regasm regsvr32 vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-04-20T19:39:00Z UTC
Last seen:
2026-09-23T17:58:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
.NET source code contains potential unpacker
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
9 match(es)
Tags:
.Net CAB:COMPRESSION:MSZIP Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.20 SOS: 0.25 SOS: 0.26 SOS: 0.28 SOS: 0.34 Win 32 Exe x86
Threat name:
Win32.Trojan.Yogi
Status:
Malicious
First seen:
2026-06-14 09:11:47 UTC
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in Windows directory
Adds Run key to start application
Drops desktop.ini file(s)
Checks computer location settings
Executes dropped EXE
Unpacked files
SH256 hash:
c73b8cb9c3a35b29d83749da7530033f036cc1cbd7b52d442f35b39e4b1cbae9
MD5 hash:
71947d95ac64782101ba0ccf8d6bea36
SHA1 hash:
c7fbfd2621121c8e655b25bea4f99711aa6cf70b
SH256 hash:
f5dbca4a2a33934d2539730944afc06a9874743caf3f0ed969ca60e61cc14f30
MD5 hash:
e55704a5e9b8b73cb891a7b3d715d130
SHA1 hash:
4a9fd72970937e896d0740d5c916d444e4aa8c22
SH256 hash:
bbbf0793868c3bff709989439b7e66a849507de322e7e5687f8d574fac62d8e0
MD5 hash:
ac281f7e293c20fd21aeba9064e04fae
SHA1 hash:
80489cb9dd28009da1631c57d8ffcd8e7e30de43
Detections:
SUSP_NET_Large_Static_Array_In_Small_File_Jan24
SH256 hash:
e4c2e8051573001bb120f17a72e3b8d6a98672931cd4260c12d031ae19c16c63
MD5 hash:
d0c278b749bad13d215b387fffff69f1
SHA1 hash:
3f75cc2a81c838dc05e5273ec786e91d44ef642a
SH256 hash:
46338d15191e130ec9f33f329081fb45e224b9c7e333701baa409337d5c9faee
MD5 hash:
fa9a27a0430e4b8c0861773f889342c0
SHA1 hash:
279bec558e6dccbd5185749eee393c8dc646db8d
SH256 hash:
a4009288982e4c30d22b544167f72db882e34f0fda7d4061b2c02c84688c0ed1
MD5 hash:
7c359500407dd393a276010ab778d5af
SHA1 hash:
4d63d669b73acaca3fc62ec263589acaaea91c0b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:win_dotnet_vb_stealer_rat
Author:Arrbat
Description:Detects .NET/VB executables with stealer/RAT capabilities (sockets, HTTP, processes, registry, etc).

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe c73b8cb9c3a35b29d83749da7530033f036cc1cbd7b52d442f35b39e4b1cbae9

(this sample)

  
Delivery method
Distributed via web download

Comments