🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5aa43a733cb278791a8f543bc5bac8d47bdee7e4a449c5d26297bcdb686ba4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: d5aa43a733cb278791a8f543bc5bac8d47bdee7e4a449c5d26297bcdb686ba4e
SHA3-384 hash: 52683c7d6a5c060af8b91552f13ea9747a96cbbd11b4f904c123f0b757fe8bff030cab3957f9e0bc6b191091802305c7
SHA1 hash: 39aff81e8e5fa8f2ddc7e6e845b8c622f243c3c3
MD5 hash: db899c6a07fffdec0413a99d0e2e1480
humanhash: seventeen-floor-orange-louisiana
File name:d5aa43a733cb278791a8f543bc5bac8d47bdee7e4a449c5d26297bcdb686ba4e.dll
Download: download sample
File size:4'812'816 bytes
First seen:2026-10-05 01:55:55 UTC
Last seen:Never
File type:DLL dll
MIME type:application/vnd.microsoft.portable-executable
imphash 0392aa966668f99fe783c0ba6bdd509a
ssdeep 98304:yCMWmcKfST5t+BceThTHfaCCUqmJPCYvboB1fdmyz:BMWKfU+BcUTHCCCfqCiUffnz
TLSH T111263349BADB025DD89672704F6AFD7EB2B92CCC4204DC4DD44DE587E8B2729703A90E
TrID 21.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
21.2% (.EXE) Win64 Executable (generic) (6522/11/2)
16.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
14.6% (.EXE) Win32 Executable (generic) (4504/4/1)
6.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter Kejult
Tags:dll dllHijack hijack

Intelligence


File Origin
# of uploads :
1
# of downloads :
446
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Verdict:
Malicious
File Type:
dll x32
First seen:
2026-10-04T23:44:00Z UTC
Last seen:
2026-10-06T19:45:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2026-10-05 01:56:22 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
19 of 24 (79.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
d5aa43a733cb278791a8f543bc5bac8d47bdee7e4a449c5d26297bcdb686ba4e
MD5 hash:
db899c6a07fffdec0413a99d0e2e1480
SHA1 hash:
39aff81e8e5fa8f2ddc7e6e845b8c622f243c3c3
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DLL dll d5aa43a733cb278791a8f543bc5bac8d47bdee7e4a449c5d26297bcdb686ba4e

(this sample)

  
Delivery method
Distributed via web download

Comments