MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GCleaner


Vendor detections: 14


Intelligence 14 IOCs YARA 12 File information Comments

SHA256 hash: cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c
SHA3-384 hash: 9828702d2217f66e080d357d8844a2d99492e761aecc6f6271ea286c494229bff385dc8ace08b663d0bf6fe462e888d9
SHA1 hash: 34b5e8d7449ce558ec9aafc624e996844614a614
MD5 hash: f651e9225960daeb8dfb96c3da275294
humanhash: cat-beryllium-connecticut-five
File name:cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c
Download: download sample
Signature GCleaner
File size:979'968 bytes
First seen:2026-07-29 10:25:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'150 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:enODWmdY07kLqqUIgHYBzGZboBpMPQUeKRWD0Uy88PwPl:2KY0djIEYBzgborMPRRdUy8
TLSH T1362522A157EAC117C548033159E2E37203B8CE88F963DA6B5FDDAEC7B92375A5C41382
TrID 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.4% (.EXE) Win64 Executable (generic) (6522/11/2)
4.4% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon 44302c2c70703002 (3 x RemusStealer, 2 x GCleaner, 1 x PhantomStealer)
Reporter JAMESWT_WT
Tags:80-76-49-77 exe gcleaner StealC-v3

Intelligence


File Origin
# of uploads :
1
# of downloads :
163
Origin country :
IT IT
Vendor Threat Intelligence
Malware configuration found for:
NETReactor RoboSki
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Deleting a recently created file
Connection attempt to an infection source
Sending an HTTP GET request to an infection source
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-18T17:23:00Z UTC
Last seen:
2026-07-30T07:04:00Z UTC
Hits:
~100
Verdict:
Malware
YARA:
12 match(es)
Tags:
.Net .Net Obfuscator .Net Reactor Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.67 Win 32 Exe x86
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2026-07-18 22:20:38 UTC
File Type:
PE (.Net Exe)
Extracted files:
12
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:amadey family:donutloader family:gcleaner family:remus_stealer defense_evasion discovery execution installer loader persistence spyware stealer themida trojan
Behaviour
Modifies registry class
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
SmartAssembly .NET packer
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks installed software on the system
Checks whether UAC is enabled
Maps connected drives based on registry
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Themida packer
Downloads MZ/PE file
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Detects Amadey x86-bit Payload
Detects DonutLoader
Family: Amadey
Family: DonutLoader
Family: GCleaner
Family: Remus
Process spawned unexpected child process
Malware Config
C2 Extraction:
185.156.73.98
45.91.200.135
http://91.92.242.236
http://zelpx.garden:9895
http://fimmora.surf:6504
http://tzpx.courses:4437
Unpacked files
SH256 hash:
cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c
MD5 hash:
f651e9225960daeb8dfb96c3da275294
SHA1 hash:
34b5e8d7449ce558ec9aafc624e996844614a614
SH256 hash:
10d0ad83a6f380325f2b3a49365fc89a217f355bd13305945d104d6f5c068bb9
MD5 hash:
87490a294f37fbd4a2d5397eb5a7eb28
SHA1 hash:
441a896374a9c99358fc8ff595b8df759726e16c
Detections:
GCleaner
SH256 hash:
67aa6bceb514ca8b3bc4e9990d2f2993d3effbdcc91a4e06bef7f502ac0ec524
MD5 hash:
4819e481a6615043610b4f8c027b553e
SHA1 hash:
56f2f07fab610779d12df2f84f128449a06c4417
SH256 hash:
281f0a31109ba3566ae24aad9d51a96464ffc1d21e36b6b6772663df2f0faac0
MD5 hash:
dde879de3fd7eb5674e79b43c6f5722d
SHA1 hash:
63a6adfa2f3d970779f8f77c69c9da620b52f3e4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments