MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 df9dcd5d8873661504de9f43c747aeedaa1b67cf3fd7dc265c23800e9ecdee21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Smoke Loader
Vendor detections: 16
| SHA256 hash: | df9dcd5d8873661504de9f43c747aeedaa1b67cf3fd7dc265c23800e9ecdee21 |
|---|---|
| SHA3-384 hash: | 5da6a5f839fc5ed88a3b341d9dca6e4cd75c75d55a9229ee8ec91269b2342706f1e407f816ff555e2975106db7a26a97 |
| SHA1 hash: | b18f47061447b1b0c3089c1d123e57dde42ff7f4 |
| MD5 hash: | 670ec9ca8e0fd5d16f53c2cf97d0d6d9 |
| humanhash: | harry-sierra-asparagus-july |
| File name: | file |
| Download: | download sample |
| Signature | Smoke Loader |
| File size: | 2'595'840 bytes |
| First seen: | 2026-04-27 18:31:25 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'237 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger) |
| ssdeep | 49152:R9YCnrrYfstBOnJ0lAAPW1HZMUk2HmzaIv7OvZT/8A1D9bE1o8raOCQvVoMSbA8:Xlr00tealAAPW1Dk2Hmnv70Z7dKragVR |
| Threatray | 3 similar samples on MalwareBazaar |
| TLSH | T168C533998919E45AC8D723312A35D3B157B48DFEED60C787C4FA2CEF78082F85868917 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | 54e64e dropped-by-amadey exe Smoke Loader |
Intelligence
File Origin
USVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
8a249e7566f513e34498a82593b400fe5d279ee7687cc52b4a8a709b88d77313
197c9b2fe8116d8e9329c5ab49f7fa2a900d27704bb8d36da9d1bc77f2239b07
b5cc8276cff50bd4462303b5b0d2d4885cc1a6ba4a812fe7c4443afde8a76f3e
4cbc79702cdc46953a14237c27ab6a81c8e46895acff1119a93a9912b4281065
042f6d8fff507d22bc7a6c7568cfdb9fb48cd9fe1c0eca4c6982f58e22b63dd8
12991ee152aeccaadf10634e11017eab2ecf13b3853272a46a7f7e8c5dec2507
df9dcd5d8873661504de9f43c747aeedaa1b67cf3fd7dc265c23800e9ecdee21
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.