🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eafa0e478cb22bda6b2b1c591e2f856fbc1aa0f808611a6087a898eaeab9f5fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RustyStealer


Vendor detections: 10


Intelligence 10 IOCs YARA 57 File information Comments

SHA256 hash: eafa0e478cb22bda6b2b1c591e2f856fbc1aa0f808611a6087a898eaeab9f5fd
SHA3-384 hash: b5d0c4ddabd18a67e4193a20451ce9f06fa397a623fdc3c951b897c88aae09a31f6e24c6f690405766ecb2066f6e961a
SHA1 hash: 5c6715f77529d597c6367aab194ae3257247f632
MD5 hash: 8e93d7eb49d43ea86aa866e470da8d1c
humanhash: music-thirteen-victor-apart
File name:update.exe
Download: download sample
Signature RustyStealer
File size:3'021'696 bytes
First seen:2026-09-16 13:42:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a696a29c6402aa08007daba2443e24b2 (1 x RustyStealer)
ssdeep 49152:OtefJhakpUhKcNnMuWk3ih98Hts8MtZYt3VdZDPqyGa8TEG:OcfJhak6hKcNnM9k3iL8HS8yYt3V3Pm0
TLSH T18EE58C10F639E750D734883AB205ED524394B66D7FA801AA48A930E4AFFFFD394275E4
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter BlinkzSec
Tags:RustyStealer signed

Code Signing Certificate

Organisation:Microsoft Corporation
Issuer:Microsoft Corporation
Algorithm:sha256WithRSAEncryption
Valid from:2026-08-02T22:23:01Z
Valid to:2027-08-02T22:23:01Z
Serial number: 7618a39b8e94d10c13de8c62324b541a5f652bac
Thumbprint Algorithm:SHA256
Thumbprint: 07aced119d27acdeae1be061a9fd36569c104ce3f31046068561b424e2b0d307
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
http://172.86.84.161/update.exe
Verdict:
Malicious activity
Analysis date:
2026-09-16 13:40:47 UTC
Tags:
amsi-bypass rust evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
active-directory anti-debug anti-vm anti-vm base64 certreq certutil cmd crypto evasive eventvwr expand explorer fingerprint hacktool installutil lolbin microsoft_visual_cc msbuild mshta msiexec obfuscated obfuscated odbcconf reconnaissance reg regsvr32 rundll32 wmic wscript xor-pe xor-pe
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.PrintSpoofer
Status:
Malicious
First seen:
2026-09-16 13:40:38 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Unpacked files
SH256 hash:
eafa0e478cb22bda6b2b1c591e2f856fbc1aa0f808611a6087a898eaeab9f5fd
MD5 hash:
8e93d7eb49d43ea86aa866e470da8d1c
SHA1 hash:
5c6715f77529d597c6367aab194ae3257247f632
SH256 hash:
d9043cde7721a27faa9ec0ba1c2818d3d1e32b60f406fb4ec4f48e37c1091e55
MD5 hash:
d7d9fe85e1c8afd47a77c9f219b4a645
SHA1 hash:
bc1aa19b6752bff07e1963c9c51f3542d997f2da
Detections:
triage_rubeus INDICATOR_SUSPICIOUS_EXE_RawPaste_URL INDICATOR_SUSPICIOUS_EXE_UACBypass_EventViewer INDICATOR_SUSPICIOUS_References_SecTools INDICATOR_SUSPICIOUS_VM_Evasion_VirtDrvComb Invoke_WMIExec_Gen_1
Malware family:
Invoke-TheHash
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_Debugger
Rule name:Check_OutputDebugStringA_iat
Rule name:Check_VBox_Guest_Additions
Rule name:Check_VmTools
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:Hunt_Obfuscated_Localhost_ROT
Author:Serhii Kocherhan
Description:Detects obfuscated/rotated 127.0.0.1 strings while excluding raw plaintext
Rule name:INDICATOR_SUSPICIOUS_EXE_RawPaste_URL
Author:ditekSHen
Description:Detects executables (downlaoders) containing URLs to raw contents of a paste
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_EventViewer
Author:ditekSHen
Description:detects Windows exceutables potentially bypassing UAC using eventvwr.exe
Rule name:INDICATOR_SUSPICIOUS_References_SecTools
Author:ditekSHen
Description:Detects executables referencing many IR and analysis tools
Rule name:INDICATOR_SUSPICIOUS_VM_Evasion_VirtDrvComb
Author:ditekSHen
Description:Detects executables referencing combination of virtualization drivers
Rule name:Invoke_WMIExec_Gen_1
Author:Florian Roth (Nextron Systems)
Description:Detects Invoke-WmiExec or Invoke-SmbExec
Reference:https://github.com/Kevin-Robertson/Invoke-TheHash
Rule name:Invoke_WMIExec_Gen_1_RID2E57
Author:Florian Roth
Description:Detects Invoke-WmiExec or Invoke-SmbExec
Reference:https://github.com/Kevin-Robertson/Invoke-TheHash
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Rust
Author:albertzsigovits
Description:Application written in Rust programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:reverse_http
Author:CD_R0M_
Description:Identify strings with http reversed (ptth)
Rule name:Rustyloader_mem_loose
Author:James_inthe_box
Description:Corroded buerloader
Reference:https://app.any.run/tasks/83064edd-c7eb-4558-85e8-621db72b2a24
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_PowerShell_Commands_Executed_via_Rundll32
Author:assistant
Description:Detects when rundll32.exe is used to execute PowerShell commands that may indicate malicious activity
Reference:https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_susp_powershell_via_rundll32.yml
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Win_FakeInstaller_PythonShellcodeLoader_Crepectl_2026
Author:SixHands
Description:Detects the analyzed fake installer sample using .key config, XOR key, and Python/fiber shellcode loader traits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RustyStealer

Executable exe eafa0e478cb22bda6b2b1c591e2f856fbc1aa0f808611a6087a898eaeab9f5fd

(this sample)

  
Delivery method
Distributed via web download

Comments