MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd9640018fa4397115c19bba60aab5afdfddd3b6c080b93dd7d7211759caa4f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 12 File information Comments

SHA256 hash: cd9640018fa4397115c19bba60aab5afdfddd3b6c080b93dd7d7211759caa4f2
SHA3-384 hash: 56fb2501b00c907bdecaeb4544181b30dbcffb779fdeeb831bf4d74e54356a3eea579c1440b159a003ab81351e7aa777
SHA1 hash: 8530cf5c52047ed5c88c7ed512d229b608d9a8a4
MD5 hash: b18d01bddb14035225dcd1abc7d37f8b
humanhash: lima-charlie-oklahoma-whiskey
File name:proxy
Download: download sample
File size:4'171'245 bytes
First seen:2026-06-08 04:16:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:q5b+qHYjPknkDYRTACw/uG9vdnv6DYYs22qQX:cv4j08/v9JvYs2I
TLSH T1361633C08D791DA9F22242BAF5845244F0FA1BC6E454167EC337D63564B8BC3A9A0DDF
Magika zip
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
110
Origin country :
GB GB
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:putty.exe
File size:4'464'984 bytes
SHA256 hash: fffa291363c6f4dd7695d56559bff754512cbdd4cc15a55bc4f34cb6006df9e3
MD5 hash: 683103409851fff2be650955eaa6908d
MIME type:application/x-dosexec
File name:proxy.lnk
File size:1'870 bytes
SHA256 hash: 9bbe1c1d58c05e9ae0d91c06b1d47c994e90866a12e584fb3004f6223885b30b
MD5 hash: 8edd81a60831c55a659d6e17638f2dee
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
trojware patched packed
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-08T01:21:00Z UTC
Last seen:
2026-06-08T12:59:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Patched.md
Gathering data
Threat name:
Win32.Worm.Ramnit
Status:
Malicious
First seen:
2026-06-08 04:16:23 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
31 of 36 (86.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery upx
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
UPX packed file
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:SUSP_Putty_Unnormal_Size_RID3086
Author:Florian Roth
Description:Detects a putty version with a size different than the one provided by Simon Tatham (could be caused by an additional signature or malware)
Reference:Internal Research
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip cd9640018fa4397115c19bba60aab5afdfddd3b6c080b93dd7d7211759caa4f2

(this sample)

  
Delivery method
Distributed via web download

Comments