MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dbf03ba27ac911cecc5e5f4402a0648d5c2e9544daddbf76fb53408a40b7f982. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GhostPulse


Vendor detections: 15


Intelligence 15 IOCs YARA 7 File information Comments

SHA256 hash: dbf03ba27ac911cecc5e5f4402a0648d5c2e9544daddbf76fb53408a40b7f982
SHA3-384 hash: 0e8d55c3e3923fc0e3f892ce785b1ae1aec2bd34208ce71be18d80d619df03e9e623aa12f96a052a8205d436516809b6
SHA1 hash: 56628e7bc693c5e331a8e9a8b92cda10c8af0bbb
MD5 hash: 0a40d85ac5a687cae796ee620e279ac7
humanhash: thirteen-seven-july-video
File name:3.exe
Download: download sample
Signature GhostPulse
File size:13'364'514 bytes
First seen:2026-07-26 14:29:55 UTC
Last seen:2026-07-26 17:28:30 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e8ac1646024d52d1534a88da2e8037cd (10 x HijackLoader, 9 x OffLoader, 8 x ValleyRAT)
ssdeep 196608:rDbMIpa95XagKNjy601Anb+TXC73JQXKBhacpyXRgof7YBMqhWT2cpKScaA:rDppe5Xf681A2C7iXOaAyhgS8MpCcp9A
TLSH T1F3D62317F28E673FE46A5A3554B29A00543FBA60691A8C73CAEC7D48CE3D4901D7EE07
TrID 50.8% (.EXE) Inno Setup installer (107240/4/30)
20.4% (.EXE) InstallShield setup (43053/19/16)
19.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.0% (.EXE) Win64 Executable (generic) (6522/11/2)
2.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 5050d270cccc82ae (113 x Adware.Generic, 81 x OffLoader, 43 x LummaStealer)
Reporter BlinkzSec
Tags:GhostPulse

Intelligence


File Origin
# of uploads :
3
# of downloads :
77
Origin country :
GB GB
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://158.94.209.17/lc/3.exe
Verdict:
Malicious activity
Analysis date:
2026-07-26 14:24:32 UTC
Tags:
inno installer delphi openssl tool stealer golang hijackloader loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Deleting a recently created file
Creating a file in the %AppData% subdirectories
Creating a process with a hidden window
Launching a tool to kill processes
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug embarcadero_delphi evasive fingerprint inno installer installer installer-heuristic packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-26T11:39:00Z UTC
Last seen:
2026-07-26T13:38:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Zenpak.sb HEUR:Trojan.Win32.Loader.gen Trojan.Win32.Penguish.sb Trojan.Win32.Delf.sb Trojan-PSW.Win32.Coins.sb
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
needle_stealer
Score:
  10/10
Tags:
family:hijackloader family:needle_stealer defense_evasion discovery installer loader spyware stealer
Behaviour
GoLang User-Agent
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Detects HijackLoader (aka IDAT Loader)
Detects NeedleStealer payload
Family: HijackLoader, IDAT loader, Ghostulse,
Family: NeedleStealer
Malware Config
C2 Extraction:
http://178.16.52.194:3000
Unpacked files
SH256 hash:
dbf03ba27ac911cecc5e5f4402a0648d5c2e9544daddbf76fb53408a40b7f982
MD5 hash:
0a40d85ac5a687cae796ee620e279ac7
SHA1 hash:
56628e7bc693c5e331a8e9a8b92cda10c8af0bbb
SH256 hash:
cf56e0677e03f123710c18286a0cb72bb02c16354ef11a0a181c3d9831c356b7
MD5 hash:
76773861257edaf4f1696941f5a24c7f
SHA1 hash:
dc9f3be8c8196bcc4add5268c06fad1fa74ee56b
SH256 hash:
422b85b5b051d6e51568b62b461f0714efc0377ef72de8d865637ef359203431
MD5 hash:
5c100518c1bc14dd079bafcc5858f37c
SHA1 hash:
08903b5e31e2767fd1ae7408ae042a033f149166
SH256 hash:
741e81a5d589c2ac51409911954bcacf6090c42e41638feb0c062f9d2e262ba2
MD5 hash:
f97039798f6c4ff6820a2daa9af6d197
SHA1 hash:
0b479dc2e012779ea1e10a7cc136dac394117ec3
SH256 hash:
b1afc317fd12cae01719204328107262db7551934539949d1b9cc87ffee0845f
MD5 hash:
b6cdac2314a59769a330b57cef0beb46
SHA1 hash:
7897a60a70394e951a99a4278563001c136feb64
SH256 hash:
2d7b5e8a7a0e403592d69b8309f6008afffba727e7d5cc75fabf67cf29ea2b82
MD5 hash:
4ae0ffea8b301270d28226948d0f4fd5
SHA1 hash:
7c1a764adb3e176b4dc0b4447426ae2333dc0ac6
SH256 hash:
9f690d225397a105b911dcc6d5f2180992bc07ee4d03670a33adaea7ff785f6f
MD5 hash:
bcf4e158dfe197a4ef9dd2fa5e28c5d8
SHA1 hash:
7f9656d694538e40ff0a3c7b67bfa0ecd3eb8010
SH256 hash:
a5ec3517b78be7fd18b24fea7c79fbf948eda181fc3cb9497e1654e8a8362044
MD5 hash:
4650d4e4e24755806ca16e0a30c76de7
SHA1 hash:
8b7e25d093425535bf526890dad6f84f28743421
SH256 hash:
4789c3f7fd41026efd0c7135b9df3356e3f8a89c2f6c4db3aff6473890ef1e45
MD5 hash:
9c7dd6d2f612250bd8c947ce4a09f101
SHA1 hash:
e8b071ea32bc3ed49687497aee7bcf43544cb182
SH256 hash:
a9c879d4dee96ba23b7bf31fb310664320ec697e1d2a0841c20efa28f28b504a
MD5 hash:
edccd87bcd8c7fba8cc86bf5126a918d
SHA1 hash:
ffaa3386da5282e2beff45dfdd4b24f9d7c2a271
SH256 hash:
08a93ad91061aeda02121ae6a4fc9ec024f612e39626c615fd5f3765957608a4
MD5 hash:
2e259afb699d02eecfa0817e791e3324
SHA1 hash:
3873b36b6b1257dfa6543124383e932d553126a4
SH256 hash:
a6edb3fb6d21dd461da3767a7995034e208f7d6b08997f6cf7ee7b0ea833a8f0
MD5 hash:
cabb58bb5694f8b8269a73172c85b717
SHA1 hash:
9ed583c56385fed8e5e0757ddb2fdf025f96c807
SH256 hash:
68bee500e0080f21c003126e73b6d07804d23ac98b2376a8b76c26297d467abe
MD5 hash:
d4dae7149d6e4dab65ac554e55868e3b
SHA1 hash:
b3bea0a0a1f0a6f251bcf6a730a97acc933f269a
Malware family:
GHOSTPULSE
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GhostPulse

Executable exe dbf03ba27ac911cecc5e5f4402a0648d5c2e9544daddbf76fb53408a40b7f982

(this sample)

  
Delivery method
Distributed via web download

Comments