MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8889ebbf9516b00d148dfd3b2aee781deb30d27f654039903d31a8ff39d1f4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GodPotato


Vendor detections: 9


Intelligence 9 IOCs YARA 7 File information Comments

SHA256 hash: c8889ebbf9516b00d148dfd3b2aee781deb30d27f654039903d31a8ff39d1f4e
SHA3-384 hash: 597ddbaef2afdfe320fd7b534bd9f6dc29ba0a88f690f5ec6d1cacac3c18851dd4cd39b52002cb2817add21bde05eb94
SHA1 hash: b1e46ed3f539868edb60e25b523e77dea71868c2
MD5 hash: 2e4973a854f88682666c77394ec3e61e
humanhash: oranges-violet-magazine-lion
File name:gp2.bin
Download: download sample
Signature GodPotato
File size:59'392 bytes
First seen:2026-06-11 19:46:26 UTC
Last seen:2026-06-11 19:48:47 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'067 x AgentTesla, 20'019 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 1536:R1qjvtmwUEzGtNmgkWQdMQanDz2OZK600QmA7U6Y:QwATg5QanDz2O7A7U6Y
TLSH T1B7431B0066B99661D1DCC6B9E0F9170243F3600E76B6F7A60EDD82DE2F5778292133DA
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter skocherhan
Tags:161-248-87-10 exe GodPotato opendir

Intelligence


File Origin
# of uploads :
3
# of downloads :
136
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
gp2.bin.exe
Verdict:
No threats detected
Analysis date:
2026-06-11 19:50:04 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 masquerade privilege reconnaissance
Verdict:
Malicious
File Type:
exe x32
Detections:
HEUR:HackTool.MSIL.JPotato.gen HEUR:HackTool.MSIL.GodPotato.a
Gathering data
Threat name:
ByteCode-MSIL.Trojan.GodPotato
Status:
Malicious
First seen:
2026-06-08 17:50:26 UTC
File Type:
PE (.Net Exe)
AV detection:
20 of 36 (55.56%)
Threat level:
  5/5
Result
Malware family:
godpotato
Score:
  10/10
Tags:
family:godpotato hacktool
Behaviour
Detects GodPotato
Family: GodPotato
Unpacked files
SH256 hash:
c8889ebbf9516b00d148dfd3b2aee781deb30d27f654039903d31a8ff39d1f4e
MD5 hash:
2e4973a854f88682666c77394ec3e61e
SHA1 hash:
b1e46ed3f539868edb60e25b523e77dea71868c2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Hacktool_GodPotato_5f1aad81
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments