MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnappyClient


Vendor detections: 14


Intelligence 14 IOCs YARA 1 File information Comments

SHA256 hash: c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a
SHA3-384 hash: 363c94b793ebe52e41abf535b96372758293ba93c2b25dd9740b58bcceff5456e10cb5ae00e4b129dc14efe0ccf1274b
SHA1 hash: 4ef9c4468fd4f3ac58a083393e64dcc093ebb3c2
MD5 hash: 1467f5f92f91eb363cfaf1c902ffb0a2
humanhash: oranges-burger-jupiter-solar
File name:setup.exe
Download: download sample
Signature SnappyClient
File size:10'417'632 bytes
First seen:2026-08-22 00:13:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b5a014d7eeb4c2042897567e1288a095 (24 x HijackLoader, 23 x GhostPulse, 14 x ValleyRAT)
ssdeep 196608:+ppHDvWq069kN6ncZi1UGS4M4RoLEvL10dshbJC7X9V0IvTahm8x:+pp2GK6cb0MNL+p0oy91vWhNx
TLSH T161A633533B46A4F1E02A9A316FC7DB0702B7C77D1615CE7B61921ECEACA30A11A475CE
TrID 42.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
16.8% (.EXE) Win64 Executable (generic) (6522/11/2)
13.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon c292ecd8f2f6fe1c (23 x GhostPulse, 23 x HijackLoader, 12 x Vidar)
Reporter aachum
Tags:exe HIjackLoader SnappyClient vidar YodaTeam


Avatar
iamaachum
https://wscnren.co/ => https://mega.nz/file/r3wxybIS#y2GqrsLW12ong06f3Z0cslBsxGILQx18aEN1ffX84jg

SnappyClient C2: yoda-time.ink (144.31.40.42:3333)
Vidar C2:
167.233.78.24:443
https://telegram.me/s11yme
https://dev.epicgames.com/community/api/user_profiles/profile.json?hash_id=roAjr
https://hbd.sm188dnsxx.top/

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a.zip
Verdict:
Malicious activity
Analysis date:
2026-08-22 07:42:08 UTC
Tags:
arch-exec hijackloader loader snappyclient rat stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Creating a file in the %AppData% subdirectories
Deleting a recently created file
Unauthorized injection to a recently created process by context flags manipulation
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context adaptive-context fingerprint installer installer installer-heuristic microsoft_visual_cc overlay packed reconnaissance
Result
Threat name:
HijackLoader, SnappyClient, Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Early bird code injection technique detected
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Unusual module load detection (module proxying)
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Writes to foreign memory regions
Yara detected HijackLoader
Yara detected SnappyClient
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1962077 Sample: setup.exe Startdate: 22/08/2026 Architecture: WINDOWS Score: 100 85 yoda-time.ink 2->85 87 yoda-cool.club 2->87 89 4 other IPs or domains 2->89 101 Suricata IDS alerts for network traffic 2->101 103 Found malware configuration 2->103 105 Antivirus detection for dropped file 2->105 107 7 other signatures 2->107 11 setup.exe 14 2->11         started        signatures3 process4 file5 69 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32 11->69 dropped 71 C:\Users\user\AppData\Local\...\msvcr100.dll, PE32 11->71 dropped 73 C:\Users\user\AppData\Local\...\msvcp_win.dll, PE32 11->73 dropped 75 7 other malicious files 11->75 dropped 14 Builder-Turbo.exe 13 11->14         started        process6 file7 77 C:\ProgramData\ORCLruntime\ucrtbase.dll, PE32 14->77 dropped 79 C:\ProgramData\ORCLruntime\msvcr100.dll, PE32 14->79 dropped 81 C:\ProgramData\ORCLruntime\msvcp_win.dll, PE32 14->81 dropped 83 7 other malicious files 14->83 dropped 137 Switches to a custom stack to bypass stack traces 14->137 139 Found direct / indirect Syscall (likely to bypass EDR) 14->139 18 Builder-Turbo.exe 20 14->18         started        signatures8 process9 file10 55 C:\Users\user\AppData\Roaming\...\memu.exe, PE32 18->55 dropped 57 C:\Users\user\AppData\...\ucrtbase.dll, PE32 18->57 dropped 59 C:\Users\user\AppData\...\msvcr100.dll, PE32 18->59 dropped 61 10 other malicious files 18->61 dropped 109 Modifies the context of a thread in another process (thread injection) 18->109 111 Found hidden mapped module (file has been removed from disk) 18->111 113 Maps a DLL or memory area into another process 18->113 115 2 other signatures 18->115 22 WavFactory.exe 15 9 18->22         started        26 Builder-Turbo.exe 7 18->26         started        29 memu.exe 18->29         started        signatures11 process12 dnsIp13 91 167.233.78.24, 443, 49735, 49763 HETZNER-ASDE Germany 22->91 121 Early bird code injection technique detected 22->121 123 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 22->123 125 Found many strings related to Crypto-Wallets (likely being stolen) 22->125 135 10 other signatures 22->135 31 chrome.exe 22->31         started        34 cmd.exe 22->34         started        36 cmd.exe 22->36         started        43 6 other processes 22->43 63 C:\Users\user\AppData\Roaming\...\memu.exe, PE32 26->63 dropped 65 C:\Users\user\AppData\Local\...\D8B4B89.tmp, PE32 26->65 dropped 67 C:\ProgramData\OrbitDoc.exe, PE32 26->67 dropped 127 Found hidden mapped module (file has been removed from disk) 26->127 129 Maps a DLL or memory area into another process 26->129 131 Switches to a custom stack to bypass stack traces 26->131 38 OrbitDoc.exe 5 26->38         started        41 memu.exe 3 26->41         started        133 Unusual module load detection (module proxying) 29->133 file14 signatures15 process16 dnsIp17 93 192.168.2.8 unknown unknown 31->93 45 chrome.exe 31->45         started        47 chrome.exe 31->47         started        49 conhost.exe 34->49         started        51 conhost.exe 36->51         started        95 yoda-time.ink 144.31.40.42, 3333, 49742, 49747 EVEOSABR France 38->95 97 example.com 172.66.147.243, 49739, 49750, 49753 CLOUDFLARENET-CloudflareIncUS Canada 38->97 99 127.0.0.1 unknown unknown 38->99 117 Unusual module load detection (module proxying) 38->117 119 Switches to a custom stack to bypass stack traces 38->119 53 conhost.exe 43->53         started        signatures18 process19
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout SFX 7z Win 32 Exe x86
Threat name:
Win32.Trojan.Penguish
Status:
Malicious
First seen:
2026-08-21 21:52:03 UTC
File Type:
PE (Exe)
Extracted files:
37
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader credential_access discovery loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Detects HijackLoader (aka IDAT Loader)
Family: HijackLoader, IDAT loader, Ghostulse,
Unpacked files
SH256 hash:
c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a
MD5 hash:
1467f5f92f91eb363cfaf1c902ffb0a2
SHA1 hash:
4ef9c4468fd4f3ac58a083393e64dcc093ebb3c2
SH256 hash:
51b3e54f882d444231fbb236f0e976b0bf7dcd7a652dcc682ca4158a4a28e5bc
MD5 hash:
0981de6d786c0731099e1ff8e4745a0d
SHA1 hash:
0ae829b560e77ddb62a8d58539c2001e1e89751e
SH256 hash:
6a6f79e06e223e55dd952cce0818577b3a495df0baea7ac2b63eb04a934d7471
MD5 hash:
c02a264656023647c96987362d08d660
SHA1 hash:
0db35d4a52d938e5519f7a8304f56a7e5f0c33b9
SH256 hash:
4dc76bbc8d1e95698782a7a763300f3f815cea3bd6bbf2733f8dc4c035c59c3d
MD5 hash:
6a613c397b253be773598f0df61c5058
SHA1 hash:
36fc4b4976546b7d210f8da8b4a9fc8c7a673aa6
SH256 hash:
e08d46dd11a25792c64f71fe30423d7e5a41d430ec198bb2b1d136ae05f49739
MD5 hash:
2ed1be5c14585fbe4a257eee3abf1c9f
SHA1 hash:
532f0f737d4fefaae050655891a3ca8050167489
SH256 hash:
f603e0a0b87b41cc34acf0702777654dbee57e7a45ae801674082858fadd4f0f
MD5 hash:
f77e865dfe912797bb98be10e64272db
SHA1 hash:
5cd3556c3d5273fe96831f3ccd04b4f0e6a72036
SH256 hash:
7dab09e1a4ea188e912aceb73ae5ac08d280f900d77a882df528c9f8f8f8f93c
MD5 hash:
b69d4f90acafdfe9f941568a56e7c857
SHA1 hash:
6fa4099bd4c79ee669eb5a272b5c79257315cc9d
SH256 hash:
50fb0ef5569f08d1e61193d0f473d180f039a322505da33c0e95aeea76e45e11
MD5 hash:
6ffa213e2ae0be59feccbaf3e8c8749c
SHA1 hash:
8cde4b6cb1576e3a67a96366414c70c2ed54909e
SH256 hash:
eadc223b8bafb65b50f81d65ddf4db69ea44928dead7faef37338e069ddb427c
MD5 hash:
88ceb7f3e61eae3a7b8b70f1f56ad491
SHA1 hash:
b7526ac840dd92e823040abd31b93ea6b3b84f3c
SH256 hash:
3abfe47a459adb13da25c8a96d9381215b75603d50d5288d916e98996d4260c6
MD5 hash:
6d3f1ec185545b22a7397b65817b71d1
SHA1 hash:
c4ab14975e5b4433d9ecbf862defa0e036f5c85d
SH256 hash:
d8165602505751cc75f74dd61b46ab4433681de6929d435794ed927bfa83ae64
MD5 hash:
0d787699d43dbbad4fb330cd32a07f9a
SHA1 hash:
e6eb6ed4ab2cb4102f05ad275ee1324ecbb286a1
SH256 hash:
bf69ca50d8137b6e02e41755eb1d35b0b63fd3e81a2c466fff0375d55e1927a5
MD5 hash:
6e144ab2aaff763d8bee927a6a22b46d
SHA1 hash:
09c0a6ab4a5397b0166815f5b38a43a04d582302
SH256 hash:
a6edb3fb6d21dd461da3767a7995034e208f7d6b08997f6cf7ee7b0ea833a8f0
MD5 hash:
cabb58bb5694f8b8269a73172c85b717
SHA1 hash:
9ed583c56385fed8e5e0757ddb2fdf025f96c807
SH256 hash:
68bee500e0080f21c003126e73b6d07804d23ac98b2376a8b76c26297d467abe
MD5 hash:
d4dae7149d6e4dab65ac554e55868e3b
SHA1 hash:
b3bea0a0a1f0a6f251bcf6a730a97acc933f269a
Malware family:
HijackLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SnappyClient

Executable exe c77dc176b6b643e833ce40829cfbc783b7a0ec317ec12e35095e6523dfb73d8a

(this sample)

  
Delivery method
Distributed via web download

Comments