MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Fuery


Vendor detections: 14


Intelligence 14 IOCs YARA 4 File information Comments

SHA256 hash: d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a
SHA3-384 hash: 0012ed42e3b559c9e9c30e499731fb5fdf907c0187fa5291d1414accbab39ad4f000cbdd404b82dff947bc2ac6cebdeb
SHA1 hash: d257ff6bac266a0319f21630daca08440f8c911d
MD5 hash: 8e4c07963077228de130111ade5705e4
humanhash: maryland-artist-burger-shade
File name:file
Download: download sample
Signature Fuery
File size:1'042'432 bytes
First seen:2026-02-13 20:53:44 UTC
Last seen:2026-02-13 21:23:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'799 x AgentTesla, 19'718 x Formbook, 12'278 x SnakeKeylogger)
ssdeep 24576:nsWguQrHxEm+TdUwH8i1U1hN/tLGXwCgpLo8hbVictUY:nsPuYHxGOKmj/tV/Qc
Threatray 151 similar samples on MalwareBazaar
TLSH T152252265768CCC06D5AD07F16A70E33457B5AE9E6822D21AEFCFADF7B44A3420848353
TrID 35.4% (.EXE) Win64 Executable (generic) (10522/11/4)
22.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.1% (.EXE) Win32 Executable (generic) (4504/4/1)
6.9% (.ICL) Windows Icons Library (generic) (2059/9)
6.8% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Bitsight
Tags:dropped-by-amadey exe fbf543 Fuery


Avatar
Bitsight
url: http://130.12.180.43/files/7974514863/TCkbvmV.exe

Intelligence


File Origin
# of uploads :
14
# of downloads :
177
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
_d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a.exe
Verdict:
Malicious activity
Analysis date:
2026-02-13 20:56:29 UTC
Tags:
auto-reg fuery

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
phishing delphi spam
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
krypt obfuscated packed
Result
Gathering data
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.29 Win 32 Exe x86
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2026-02-13 20:54:16 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
10 of 36 (27.78%)
Threat level:
  1/5
Result
Malware family:
Score:
  10/10
Tags:
family:fuery discovery persistence trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Adds Run key to start application
Loads dropped DLL
Downloads MZ/PE file
Fuery
Fuery family
Malware Config
C2 Extraction:
http://let.mebeyourfriend.digital/
http://if.youwannabemylover.life/
http://make.mydaymakemyday.info/
http://iahfi.visbxskagt.com/
http://laf.oahgsfwklg.top/
http://smachrie1.weinerbuyout.top/
http://sackless2.backspacersasine.sbs/
http://recondole3.compositesclosetful.xyz/
http://dietaries4.permeatedicelanders.today/
http://epanadiplosis5.misdateswampanoag.cyou/
http://invoke6.escrimesesquipedal.digital/
http://bordrage7.kafkaesquebozo.info/
http://stacher8.disequilibrationaproctous.top/
http://scoliidae9.
Unpacked files
SH256 hash:
d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a
MD5 hash:
8e4c07963077228de130111ade5705e4
SHA1 hash:
d257ff6bac266a0319f21630daca08440f8c911d
SH256 hash:
48fa91de316a3b8b9b173548ff297a529e8045cfba133655cb8d7bf2517df628
MD5 hash:
54f2d8dcde429e9fa2c0cef39b6bb0e7
SHA1 hash:
1b0181a02d9f36613fdd5170d1b84a5a8358b2af
SH256 hash:
9c5e4bc4f3b9f282b6178afabc3d3fa403858583c51bc10c0457ec72401b61f8
MD5 hash:
222afb9f8ab1f3069466299485087794
SHA1 hash:
a256eb1a0349b92c3eca8a23f0536dc85ac01527
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
49440442bb8d826446a399ec1ea9abd46fd6872d593e5b41039af53adade857d
MD5 hash:
3263f3be6bb0f34462edbd0922f6d07d
SHA1 hash:
db3c04b0dff26b283f543f62152592867b68a7bc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Fuery

Executable exe d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

Comments