MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7e987c4a9d74af9ccdc5405cecdea301b0a764e1a5cae1dbf4a4f76104edd14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 3 File information Comments

SHA256 hash: d7e987c4a9d74af9ccdc5405cecdea301b0a764e1a5cae1dbf4a4f76104edd14
SHA3-384 hash: f6e41906145398016640486d66bb9fae89a56e361a404aabe046295a03e40ab7d90d6a1abbdcebe00a002e5517aaa223
SHA1 hash: 03e3fb657b7d311f3b062cfc209060e5147b5416
MD5 hash: 8ca77178143099129d469127d0478b46
humanhash: pizza-neptune-tennis-hawaii
File name:file
Download: download sample
File size:627'200 bytes
First seen:2026-05-17 16:43:33 UTC
Last seen:2026-05-18 02:02:36 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0a811601677b0fef62610ac5d6438e32
ssdeep 12288:aCtaagUhtUSOosFt/RcJpudr+mN5CqVphv/AcGqAKGB0:dt5dhtUSoFt/uf2d9wYpGB0
Threatray 22 similar samples on MalwareBazaar
TLSH T17FD4238EFA1E0513D73BD6B2D1CE4BB7D365A413669F7918C83052C963AA9014CB271F
TrID 34.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
13.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
13.7% (.EXE) Win64 Executable (generic) (6522/11/2)
10.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 60c09d9998b2d9d5
Reporter Bitsight
Tags:a dropped-by-gcleaner exe MIX4.file


Avatar
Bitsight
url: http://158.94.209.95/service

Intelligence


File Origin
# of uploads :
6
# of downloads :
112
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_d7e987c4a9d74af9ccdc5405cecdea301b0a764e1a5cae1dbf4a4f76104edd14.exe
Verdict:
No threats detected
Analysis date:
2026-05-17 16:45:40 UTC
Tags:
netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Creating a window
Reading critical registry keys
Creating a file
Stealing user critical data
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug mingw packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-17T13:52:00Z UTC
Last seen:
2026-05-17T20:54:00Z UTC
Hits:
~100
Detections:
Trojan.Win64.DonutInjector.sb Trojan-PSW.Win32.Coins.sb Backdoor.MSIL.Agent.sb Trojan.Win64.Donut.sb Trojan.Win32.Shellcode.sb Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Disco.sb Trojan-PSW.MSIL.Stealer.sb Trojan-PSW.MSIL.PureLogs.sb Trojan-PSW.MSIL.Agent.sb Trojan.Win32.Shellcode.pox Trojan-PSW.Stealer.HTTP.C&C Trojan-Dropper.Scrop.HTTP.C&C PDM:Trojan.Win32.Generic
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.LummaStealer
Status:
Malicious
First seen:
2026-05-17 16:44:40 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
21 of 24 (87.50%)
Threat level:
  5/5
Gathering data
Unpacked files
SH256 hash:
d7e987c4a9d74af9ccdc5405cecdea301b0a764e1a5cae1dbf4a4f76104edd14
MD5 hash:
8ca77178143099129d469127d0478b46
SHA1 hash:
03e3fb657b7d311f3b062cfc209060e5147b5416
SH256 hash:
c9cd05fe0978d9a99dc01c8898e4f42c125732297a9dd1d1007d8f1b70146e66
MD5 hash:
24c92bf8f03d7bbe31c937d17cebdc25
SHA1 hash:
196f11b5d73925fb8a881fbda377fb1425aac044
SH256 hash:
741374c4418c100082ca6d34c44a3c1af670975158bdfe166ee028ba2450f06e
MD5 hash:
0fba32f1eb7eaac44eb18a0e37332383
SHA1 hash:
846fb9806735b37a0393db48537817061cb6dd2f
SH256 hash:
d0e4dc5e3ca915de0b5851854ff22360089cccb93fd4e936de5191d0f077146a
MD5 hash:
94e88e54115154787a07da0e6786ce12
SHA1 hash:
9a100cc90aef35e9582b6eb53537baf376362ca5
SH256 hash:
8a93f30ba42cf6eb230c8c25c59f2ca44a9c1577218cf68b67312971c17aea9d
MD5 hash:
04e88546d15f27ebf198fde88d3f5c8f
SHA1 hash:
aa2434379fa18afb8839697df086203f96cddc9a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe d7e987c4a9d74af9ccdc5405cecdea301b0a764e1a5cae1dbf4a4f76104edd14

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments