MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb636808cf6ea68f8732c59bee276d024c75e8c143e153a6f8351f9b2f9cd858. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 8 File information Comments

SHA256 hash: cb636808cf6ea68f8732c59bee276d024c75e8c143e153a6f8351f9b2f9cd858
SHA3-384 hash: 3a290ce7e8c5237046c70e3b5e2b43cf9cbfe7f9b466aaed08a2d5c5747582ac6cd6b551cf4af8943227a172413333cb
SHA1 hash: e7f97e9c8edfee1b22b7ad9f82c9c1e63134bf6e
MD5 hash: 3c77eddfaa3ff99bb7ff421ddb5af3b6
humanhash: equal-fourteen-five-lion
File name:RstHosts2.1.exe
Download: download sample
File size:1'363'968 bytes
First seen:2026-04-13 15:32:52 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'121 x AgentTesla, 20'133 x Formbook, 12'360 x SnakeKeylogger)
ssdeep 24576:iNbCDPZbCDP29pmQR5+so3pr9pxXUyunXrMrQWkc+YtGsURs5PjCzPA:iNbCDPZbCDP29pmQn09pNUhnXrMrrJtU
TLSH T1A055DF02B27192E1D5EA8931D8A6C61669307D515F69C69B3B38F3CA3B713C36E3834D
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
File icon (PE):PE icon
dhash icon 71e0c68cce8cf871
Reporter Anonymous
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Rst_Hosts.exe
Verdict:
No threats detected
Analysis date:
2025-07-08 20:08:54 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
95.7%
Tags:
virus micro
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug expired-cert explorer lolbin overlay packed packed unsafe vbnet
Verdict:
Clean
File Type:
exe x32
First seen:
2024-02-12T06:02:00Z UTC
Last seen:
2026-03-18T09:35:00Z UTC
Hits:
~10
Gathering data
Verdict:
Malicious
Threat:
ByteCode-MSIL.Trojan.Zilla
Threat name:
Win32.PUA.Generic
Status:
Suspicious
First seen:
2024-02-17 23:58:32 UTC
File Type:
PE (.Net Exe)
Extracted files:
28
AV detection:
17 of 36 (47.22%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
cb636808cf6ea68f8732c59bee276d024c75e8c143e153a6f8351f9b2f9cd858
MD5 hash:
3c77eddfaa3ff99bb7ff421ddb5af3b6
SHA1 hash:
e7f97e9c8edfee1b22b7ad9f82c9c1e63134bf6e
SH256 hash:
c3a0f2000fd27ae96aeaaa50296ca499fe36eb3a9f1316d591256885e0e46881
MD5 hash:
d8b2e093b527d1c5af5ff9ea7ee8bcc5
SHA1 hash:
b75f75e85c7f2d291bdd88e2e1343fab3e9c8036
SH256 hash:
2ba404c50684d59b701959a1732617dec6a6a25c8005294c0d2b3822b38479a4
MD5 hash:
85def55323cfc4a04a270127a20f4d2c
SHA1 hash:
0e6ef35f6f68be6d72e4a225494c02557d39cacc
SH256 hash:
bab0847ff7520392c538c51bc91458b93dd703d18e9e7c73804ec74dfb385c0b
MD5 hash:
5b4d91abaec729481acbafd18fa20950
SHA1 hash:
ef2224b73ae840ba41a3666a6fb132781510736c
SH256 hash:
efc97ee4739c1a8c24f459de5c0266489d8620873b7adb3c779f44967d2f13f2
MD5 hash:
e0cc9978264bbba3053ca671956d022f
SHA1 hash:
32597d12a7fb471259390313e4ce1ba29042b737
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Runtime_Broker_Variant_1
Author:Sn0wFr0$t
Description:Detecting malicious Runtime Broker
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments