MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd74507f541bcac4c44c7a1e001d5fc41864e3f2f256cec8f23cdc97d9233c06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XTinyLoader


Vendor detections: 13


Intelligence 13 IOCs YARA 6 File information Comments

SHA256 hash: dd74507f541bcac4c44c7a1e001d5fc41864e3f2f256cec8f23cdc97d9233c06
SHA3-384 hash: 237b26e8e7c6a82651126179f551b04f8478a125841fdbfdeda293f51bff9e42829cc28c926bd65225e7be79929852ac
SHA1 hash: 31f1714303a66019884fa3d4487ac10cbc50b549
MD5 hash: 1ccd26710a1c2e76fd56aebe851e5f4c
humanhash: sink-jig-south-finch
File name:dd74507f541bcac4c44c7a1e001d5fc41864e3f2f256cec8f23cdc97d9233c06
Download: download sample
Signature XTinyLoader
File size:212'992 bytes
First seen:2026-06-08 09:52:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f13163977fd6f5deecd7b6f9e7876963 (1 x XTinyLoader)
ssdeep 6144:5XZJstFS9pHhiDM7KQ5FEcq+TvxWwegc8nx+:h2S91h17KQXjq25Wuc8n8
TLSH T1D024DF9B73E531F8E1764239C8A11919E372F43606619BAF0360429A1F773E19D3AF72
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter adrian__luca
Tags:exe XTinyLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
dd74507f541bcac4c44c7a1e001d5fc41864e3f2f256cec8f23cdc97d9233c06.exe
Verdict:
Malicious activity
Analysis date:
2026-06-06 23:34:30 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
emotet agentb bazar
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file in the %temp% directory
Enabling the 'hidden' option for files in the %temp% directory
Loading a suspicious library
Sending an HTTP GET request to an infection source
Searching for synchronization primitives
Setting browser functions hooks
Connection attempt to an infection source
Unauthorized injection to a system process
Unauthorized injection to a browser process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm bazarloader explorer lolbin microsoft_visual_cc packed
Verdict:
Adware
File Type:
exe x64
First seen:
2026-05-18T15:38:00Z UTC
Last seen:
2026-05-31T20:12:00Z UTC
Hits:
~10
Detections:
HEUR:HackTool.Win32.Inject.heur
Gathering data
Threat name:
Win64.Trojan.BazarLoader
Status:
Malicious
First seen:
2026-05-18 15:22:13 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
28 of 36 (77.78%)
Threat level:
  5/5
Result
Malware family:
xtinyloader
Score:
  10/10
Tags:
family:xtinyloader loader stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Executes dropped EXE
Family: XTinyLoader
Malware Config
C2 Extraction:
62.60.226.159
Unpacked files
SH256 hash:
dd74507f541bcac4c44c7a1e001d5fc41864e3f2f256cec8f23cdc97d9233c06
MD5 hash:
1ccd26710a1c2e76fd56aebe851e5f4c
SHA1 hash:
31f1714303a66019884fa3d4487ac10cbc50b549
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments