MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd20c8c58a0b648abb515746556502b19a6fdbaaa790a65ad51570bc9001c19b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 22 File information Comments

SHA256 hash: cd20c8c58a0b648abb515746556502b19a6fdbaaa790a65ad51570bc9001c19b
SHA3-384 hash: 45dc66b3316dd7377d996606993cd96cd2a63d3f3b877461b0ca6017dd4f610b1e5d9f08676ac3e3054dfda1ff111b01
SHA1 hash: ffe43e58a333b593256b93f4c03ff4eae1ddc2ec
MD5 hash: 52a80b43e07cc9e06dea5ae299391812
humanhash: mobile-leopard-freddie-sink
File name:52a80b43e07cc9e06dea5ae299391812.exe
Download: download sample
File size:11'586'048 bytes
First seen:2026-08-06 14:20:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c1ef3c1f3bf3d5d3f0e27d9deb9bf881
ssdeep 196608:xJTRAD0yZRbcLDlTaGKLXsmWAHo3k0WaOVbhKEKZ:j4mpTavXLpYkLBbQFZ
TLSH T189C62257A3A441FCE066C279CA465D4BEB72780A03A0EEDF17D049526FA73E05E3A713
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon e89632512b30d4f4
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
138
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-06 14:52:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Connection attempt
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm base64 crypto fingerprint hacktool installer-heuristic microsoft_visual_cc overlay packed reconnaissance
Verdict:
Unknown
File Type:
exe x64
First seen:
2026-08-05T23:09:00Z UTC
Last seen:
2026-08-08T11:33:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Found direct / indirect Syscall (likely to bypass EDR)
Found potential dummy code loops (likely to delay analysis)
Hides threads from debuggers
Multi AV Scanner detection for submitted file
Tries to delay execution (extensive OutputDebugStringW loop)
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout SVG Win 64 Exe x64
Threat name:
Win64.Exploit.CVE-2019-16098
Status:
Suspicious
First seen:
2026-08-05 23:43:41 UTC
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Unpacked files
SH256 hash:
cd20c8c58a0b648abb515746556502b19a6fdbaaa790a65ad51570bc9001c19b
MD5 hash:
52a80b43e07cc9e06dea5ae299391812
SHA1 hash:
ffe43e58a333b593256b93f4c03ff4eae1ddc2ec
SH256 hash:
01aa278b07b58dc46c84bd0b1b5c8e9ee4e62ea0bf7a695862444af32e87f1fd
MD5 hash:
2d8e4f38b36c334d0a32a7324832501d
SHA1 hash:
f6f11ad2cd2b0cf95ed42324876bee1d83e01775
SH256 hash:
4fa7bb5e9261525d82441c990e06fddefa89f020acc75c55bd83dfa28d9c421a
MD5 hash:
9bf2bcd5a3a93a5064122c3ee7390c84
SHA1 hash:
d003a29c2066ce9e8528aa859d30a4a2ab5100ef
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_Debugger
Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:pe_detect_tls_callbacks
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TH_APT_EquationGroup_2026_CYFARE
Author:CYFARE
Description:Equation Group (G0020) APT malware detection - covers EquationDrug, GrayFish, DoubleFantasy, TripleFantasy, Fanny, GROK, nls_933w HDD firmware module, and Shadow Brokers tooling
Reference:https://cyfare.net/
Rule name:TH_Generic_MassHunt_Win_Malware_2025_CYFARE
Author:CYFARE
Description:Generic Windows malware mass-hunt rule - 2025
Reference:https://cyfare.net/
Rule name:Tool_FakeInstaller_2
Author:Nikos 'n0t' Totosis
Description:Detects fake installers that decrypt RC4-encrypted payloads stored in PE resources with IDs 100, 101.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments