🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea4339c87444d39328ad6e20ea2d4ded7cccd87f5dd0acfadd90f305b61912ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea4339c87444d39328ad6e20ea2d4ded7cccd87f5dd0acfadd90f305b61912ec
SHA3-384 hash: 00ba47d9b625724c705b889928c061e55a715ad9e94a06f5fb94c8c44fa8d60b8e6303c92936ac6b37f3620033d44e26
SHA1 hash: 8510b75f7fd3ce77ca33b0e8d5ddaa7c4adc7247
MD5 hash: 7d3b45e8cc20a191696311e7361daa6d
humanhash: cola-paris-social-vegan
File name:UNO-Setup.exe
Download: download sample
File size:145'587'884 bytes
First seen:2026-09-15 14:03:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 3145728:4yPlw1W+Igf/I0KdSeQAtP3lIRAQE/L4037ehjUrH05B7s1L0GIjY:y1xLL8jP3lIaBc037eH5SOY
TLSH T1E96833216381DBD5D23788335307BFA1E97962C3DE051FDAA6C338B5E2617DA582C0B6
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon c4dadadad2f492c2 (148 x GuLoader, 51 x RemcosRAT, 23 x VIPKeylogger)
Reporter NekoPunchii
Tags:electron exe stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
299
Origin country :
TR TR
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks installed software on the system
Contacts third-party web service commonly abused for C2
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe ea4339c87444d39328ad6e20ea2d4ded7cccd87f5dd0acfadd90f305b61912ec

(this sample)

  
Delivery method
Distributed via web download

Comments