MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d421cda5ce74477bcc1e0b7f02ad75a5ae7fd53811922e2113ebdba61719f973. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 16


Intelligence 16 IOCs YARA 5 File information Comments

SHA256 hash: d421cda5ce74477bcc1e0b7f02ad75a5ae7fd53811922e2113ebdba61719f973
SHA3-384 hash: 9bae735ec061c15bac6751936bffec587e36bf69a7348239be636cceefe6fa34bdb202cf2343f3f7280f0e19156f2f3e
SHA1 hash: 414192bbe4d075190f8b199a76a577d1accf39b0
MD5 hash: 943c9676e4ad29fdfec26f1aca8bc302
humanhash: bulldog-tango-pizza-alabama
File name:SecuriteInfo.com.Trojan.GenericKD.76691941.9315.16201
Download: download sample
File size:4'022'768 bytes
First seen:2025-06-22 03:20:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a94549878c259a0f21633bf9ee3fa800 (1 x Adware.Auslogics)
ssdeep 24576:ueMn96z4S/zCtTFL/QcOoPjsdkN6sLorrbUiOamUg9AB:ues6/EFccjsdPOad
TLSH T12616BC93B04394D0E82E44B4345A6CDD79A03E61A9F8086E25F036FE566F7D36CE7878
TrID 45.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.3% (.EXE) OS/2 Executable (generic) (2029/13)
18.0% (.EXE) Generic Win/DOS Executable (2002/3)
18.0% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
dhash icon 58988066ac88e070
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
507
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
74b7bf0e893610d5503068c61fdb05d8b48da82aa10c073a4027dfc34fd9f141.bin
Verdict:
Malicious activity
Analysis date:
2025-06-21 18:03:23 UTC
Tags:
lumma stealer themida attachments attc-unc loader amadey botnet evasion vidar telegram stealc lclipper clipper auto-reg rdp autoit python stegocampaign github ta558 apt payload quasar rat reverseloader netreactor purehvnc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
91.7%
Tags:
autoit emotet
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Creating a process from a recently created file
Creating a file
Running batch commands
Creating a process with a hidden window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
autoit compiled-script expired-cert installer invalid-signature overlay overlay packed packed packed packer_detected signed upx
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
84 / 100
Signature
Antivirus / Scanner detection for submitted sample
Found suspicious powershell code related to unpacking or dynamic code loading
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Reads the Security eventlog
Reads the System eventlog
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
6 match(es)
Tags:
AutoIt Decompiled Executable PE (Portable Executable) SFX 7z Suspect Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-20 19:07:21 UTC
File Type:
PE+ (Exe)
Extracted files:
111
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
UPX packed file
Checks computer location settings
Executes dropped EXE
Unpacked files
SH256 hash:
d421cda5ce74477bcc1e0b7f02ad75a5ae7fd53811922e2113ebdba61719f973
MD5 hash:
943c9676e4ad29fdfec26f1aca8bc302
SHA1 hash:
414192bbe4d075190f8b199a76a577d1accf39b0
SH256 hash:
ae3cb6c6afba9a4aa5c85f66023c35338ca579b30326dd02918f9d55259503d5
MD5 hash:
366fd6f3a451351b5df2d7c4ecf4c73a
SHA1 hash:
50db750522b9630757f91b53df377fd4ed4e2d66
SH256 hash:
ae09f111f90c3a8f91fc935f435474e2dfc1e91a46419e87bd144b9ec1eb7a48
MD5 hash:
f7dc544a3b4f5da394e0b99748e803c9
SHA1 hash:
5b3d3d48bb1d0c277937c69a9455841f79e5182f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:observer
Author:Michelle Khalil
Description:This rule detects unpacked observer malware samples.
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:upx_largefile
Author:k3nr9

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe d421cda5ce74477bcc1e0b7f02ad75a5ae7fd53811922e2113ebdba61719f973

(this sample)

  
Delivery method
Distributed via web download

Comments