🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eec6fb4f124564fea83670faf7b61140347020a3ca3eef052d4dc6bad4097893. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WailsLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: eec6fb4f124564fea83670faf7b61140347020a3ca3eef052d4dc6bad4097893
SHA3-384 hash: 5e8cb763818d51911cecffddea60d1bc0717470020c1581eed039b6f8ea8371ccbed86a51118deb7770e21c4af176991
SHA1 hash: c057e76cfc4ecd745116195def18236f94cce6c3
MD5 hash: c3a9a58d2cf4420197ebcf473a2006a2
humanhash: fruit-alpha-tango-colorado
File name:lib.dll
Download: download sample
Signature WailsLoader
File size:550'912 bytes
First seen:2026-09-12 16:57:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 55cb668e4cb6d925853efdf5dad557bf (1 x WailsLoader)
ssdeep 12288:EFcUV3MbdrSFHj8kK6JJSkUQVnUAQcNp0nFYb9kEqVdwCmMKWCVCtY27CDkUYYF6:EFcUV3admj8kK6JJSkUQVnUpcNp0nFEk
TLSH T1C6C416A7D029129CF4FAC1BDD283A567E8A7B1188B2F55DF81B103707B586E26B7C344
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 700c863333860c70 (1 x WailsLoader)
Reporter ffforward
Tags:com-server dll dropped-by-wailsloader exe native-dll WailsLoader X64


Avatar
ffforward
Stage 3 64-bit native DLL dropped by AdPayWorks WailsLoader. Exports DllRegisterServer / DllGetClassObject; not standalone executable, requires COM or rundll32 hosting.

Intelligence


File Origin
# of uploads :
1
# of downloads :
168
Origin country :
SE SE
Vendor Threat Intelligence
Gathering data
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-12 17:06:03 UTC
Tags:
evasion websocket loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm anti-vm expand lolbin
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.MintPhil
Status:
Malicious
First seen:
2026-09-12 04:49:46 UTC
File Type:
PE+ (Dll)
Extracted files:
7
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Gathering data
Unpacked files
SH256 hash:
eec6fb4f124564fea83670faf7b61140347020a3ca3eef052d4dc6bad4097893
MD5 hash:
c3a9a58d2cf4420197ebcf473a2006a2
SHA1 hash:
c057e76cfc4ecd745116195def18236f94cce6c3
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments