🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e913b436fe3debd25ed0fa24e84e313f104490be66687a584f9cc15e0b23d9c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e913b436fe3debd25ed0fa24e84e313f104490be66687a584f9cc15e0b23d9c8
SHA3-384 hash: 3cf8ecff04cc65d54ca077899a5e56253044f3f7bcaa92575c4d939a8de858e7e5bdbdf22541cfb43d2c6174240ec6fc
SHA1 hash: 208df40f867f890dc89ed646b65a62c0f55be9de
MD5 hash: 294ffbbe86b0f28145cae566ea81f52e
humanhash: mango-wisconsin-green-lake
File name:setup
Download: download sample
File size:92'367'160 bytes
First seen:2026-03-30 08:42:40 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 46ce5c12b293febbeb513b196aa7f843 (47 x GuLoader, 21 x RemcosRAT, 15 x AgentTesla)
ssdeep 1572864:di7IIuYGoq/gWC+GfLrhkWI7EWHv5UK+13dToezjLvraIfEb07lnxOQy+/3C7:di76qq/gjLrhkWI7EWPOK+1jpcGlnkKe
TLSH T1CF18338392939442DCB67C709CC3457FE4AC9EBDD2ADA11BD226E50272B0E7B153B361
TrID 27.0% (.EXE) Win64 Executable (generic) (6522/11/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.4% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon 60e098f4e6f2f8d8 (2 x MuddyWater, 1 x RedLineStealer)
Reporter SquiblydooBlog
Tags:exe signed

Code Signing Certificate

Organisation:Xiamen Longhu Sanlu E-commerce Co., Ltd.
Issuer:Sectigo Public Code Signing CA EV R36
Algorithm:sha256WithRSAEncryption
Valid from:2026-03-19T00:00:00Z
Valid to:2027-03-19T23:59:59Z
Serial number: 3d750f9ac0e074d810bcf82573950af3
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: a9f57869ed3dad317c21c32bbc5aaace86fa005b4b06c70b9bb6509bd914e682
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
146
Origin country :
US US
Vendor Threat Intelligence
Gathering data
Malware family:
n/a
ID:
1
File name:
e913b436fe3debd25ed0fa24e84e313f104490be66687a584f9cc15e0b23d9c8.bin
Verdict:
Suspicious activity
Analysis date:
2026-03-30 08:40:30 UTC
Tags:
doc-url python arch-exec arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
DNS request
Connection attempt
Creating a process from a recently created file
Sending a custom TCP request
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context blackhole installer microsoft_visual_cc overlay signed threat unknown
Verdict:
Clean
File Type:
exe x32
First seen:
2026-03-30T06:21:00Z UTC
Last seen:
2026-03-30T06:30:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments