MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 cedec56282110dfd147a834510359492d6b5d257d84479a5a197e71c3326e5a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
VIPKeylogger
Vendor detections: 17
| SHA256 hash: | cedec56282110dfd147a834510359492d6b5d257d84479a5a197e71c3326e5a8 |
|---|---|
| SHA3-384 hash: | 786ff44a03bbcfb5866dfef07b9551c2f515cebe8a2db9a614e34baf62bd178ab0db205fa4cf5905cb2a24085af0133d |
| SHA1 hash: | a8a89c3b0309d341fd543dc688baf28d72c43bf2 |
| MD5 hash: | f73123dd49c2beaca2cd3de2efc6c7ac |
| humanhash: | steak-minnesota-oranges-muppet |
| File name: | rREQUESTFORQUOTATION.exe |
| Download: | download sample |
| Signature | VIPKeylogger |
| File size: | 1'176'064 bytes |
| First seen: | 2026-02-16 05:30:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'843 x AgentTesla, 19'774 x Formbook, 12'297 x SnakeKeylogger) |
| ssdeep | 24576:cgSFJynPgKzfjEXfmRyl/OZbx3PxkA3xcf3SXy:chOPgufjEXf8x3zMB |
| Threatray | 6 similar samples on MalwareBazaar |
| TLSH | T12C45E11163ECDAA8F4BEEB39513805204BF1F917DB22EB1E6E4D41E95831B81DA57323 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe VIPKeylogger |
Intelligence
File Origin
BRVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Malware Config
Unpacked files
cedec56282110dfd147a834510359492d6b5d257d84479a5a197e71c3326e5a8
a9070022b1d28df7c94f12f8c025366cab612baba8c6424257d8feb805b0d182
401c50c10e105b44dac2079d99d7e6980639ff05511ec7e44a9e2be391dbe8a3
9dc81909455bcbe708df0d51ac1db33aed33598e7c6f37063f20264a8d818e9c
3cc3af9d88fe88e63fa15aa813dc429c8ada43063c8bbba519bf42b52b06e211
a8e2f2b1c34d1e7a6b602ba9f0f4eafd050c859d96f6d2ab2c2fd006c569aedc
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.