MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mimic


Vendor detections: 15


Intelligence 15 IOCs YARA 17 File information Comments

SHA256 hash: eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6
SHA3-384 hash: 68f088592063b2a26ef47648bec63e2e3f24e0f3d105628e0e5300c4489bb4c890bc98e811ac80b6a98e4779e37c554d
SHA1 hash: ede50e64f0afc854ce3b2f2edcc401c4a564fcb0
MD5 hash: 8eed221c03dada349c651260e2e61845
humanhash: asparagus-alaska-princess-river
File name:file
Download: download sample
Signature Mimic
File size:352'768 bytes
First seen:2026-05-26 18:10:36 UTC
Last seen:2026-05-26 19:47:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ce65a372bee233e6193587db802a7b2a (1 x Mimic)
ssdeep 6144:pO8txB35TDQtK92ZefDm+Fd0Kdd/+CDbLwL6Qgg/wAG/kaRC0y8BAJL0y5f6O:TtiefWKdd/+CPLE6Jg4AQRzy8BG6O
TLSH T15E7412A721BCA0D1F45D2CB62419C32A26454C5602331B58F7DBBAE1CE7B58BF6132F6
TrID 63.4% (.EXE) UPX compressed Win32 Executable (27066/9/6)
11.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.5% (.EXE) Win32 Executable (generic) (4504/4/1)
4.7% (.EXE) OS/2 Executable (generic) (2029/13)
4.6% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 68e0c0c4c4c4c4d8 (4 x Mimic, 1 x SalatStealer)
Reporter Bitsight
Tags:dropped-by-gcleaner exe f Mimic MIX5.file UPX


Avatar
Bitsight
url: http://158.94.209.95/service
File size (compressed) :352'768 bytes
File size (de-compressed) :884'736 bytes
Format:win32/pe
Unpacked file: c1a201cf95536c5c9a63f69793515c296e7db0b289328786e8b1cb7a03714b80

Intelligence


File Origin
# of uploads :
2
# of downloads :
125
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
PEPacker
Details
PEPacker
a UPX version number and an unpacked binary
Malware family:
n/a
ID:
1
File name:
file.exe
Verdict:
Malicious activity
Analysis date:
2026-05-26 18:13:33 UTC
Tags:
auto-reg ransomware upx smb pay2key

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
shell virus sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Сreating synchronization primitives
Creating a process from a recently created file
Creating a process with a hidden window
Adding an access-denied ACE
Launching a process
Creating a window
Running batch commands
Searching for the window
Forced system process termination
Searching for synchronization primitives
Changing a file
Reading critical registry keys
Moving a file to the %AppData% subdirectory
Modifies multiple files
Connection attempt
Launching a service
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun with the shell\open\command registry branches
Forced shutdown of a system process
Changing the Windows explorer settings
Stealing user critical data
Creating a file in the mass storage device
Preventing system recovery
Enabling autorun
Encrypting user's files
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug fingerprint keylogger masquerade microsoft_visual_cc obfuscated packed packed ransomware reconnaissance upx
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-26T12:25:00Z UTC
Last seen:
2026-05-28T10:39:00Z UTC
Hits:
~100
Detections:
Trojan-PSW.Win32.Stealer.sb Trojan-Ransom.Win32.Mimic.sb Trojan-Ransom.Win32.Encoder.sb VHO:Trojan-Ransom.Win32.Convagent.gen Trojan-Ransom.Win32.Mimic.bw PDM:Trojan.Win32.Generic Trojan.Win32.Zonidel.sb Trojan.Win32.Agent.sb Trojan-Ransom.Win32.Agent.sb Trojan-Dropper.Win32.Dapato.sb HEUR:Trojan-Ransom.Win32.Generic
Malware family:
Mimic Ransomware
Verdict:
Malicious
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-05-26 18:11:33 UTC
File Type:
PE (Exe)
Extracted files:
17
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery evasion execution persistence ransomware upx
Behaviour
Checks SCSI registry key(s)
Modifies registry class
Opens file in notepad (likely ransom note)
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System policy modification
Uses Task Scheduler COM API
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Windows directory
UPX packed file
Adds Run key to start application
Power Settings
Executes dropped EXE
Modifies system executable filetype association
Deletes System State backups
Event Triggered Execution: Image File Execution Options Injection
Clears Windows event logs
Modifies boot configuration data using bcdedit
Renames multiple (472) files with added filename extension
Unpacked files
SH256 hash:
eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6
MD5 hash:
8eed221c03dada349c651260e2e61845
SHA1 hash:
ede50e64f0afc854ce3b2f2edcc401c4a564fcb0
SH256 hash:
e37aa72bca3cecb9bdbe51cbd81ec1143bb17163088a1379a4ccb93f5d881e76
MD5 hash:
5cac4fe734fc8454ccb847e030beee38
SHA1 hash:
34298fe220e35f614b2c837cf1dc2604ab0882d6
SH256 hash:
ad80064f71d273967dcf0b14b9cd6e84d79a132231d619687d9266c7807bdfe0
MD5 hash:
a35ee23aaab26afc575ac83df9572b57
SHA1 hash:
81ea38c694ce9702faddfb961f17c1bbf628a76d
SH256 hash:
00b9c0120df0595184523a3620ef9b3c3e11fc0e61d366d7eeabb646647cfceb
MD5 hash:
bd1f243ee2140f2f6118a7754ea02a63
SHA1 hash:
cdf7dd7dd1771edcc473037af80afd7e449e30d9
SH256 hash:
0377585ec50ed2e1b3d8519be272599f31024accd20b484ddae8240e09cc83b4
MD5 hash:
13d3997b43c3d5cbafb0ff10b6f0dee1
SHA1 hash:
e650a76f3fa8d28e2ff3751ccf44d124ef2b82bd
SH256 hash:
a7c421f0c91ff3047091f26639f790be8fdd0875375bf4e9a8aa209a14ee4652
MD5 hash:
6203701bd194461c0599d87a1d709c2d
SHA1 hash:
1a57c7dcc2925ffd53d4a640dde1fdc75793f64d
SH256 hash:
9ff0c3fc2488aee23999334797ff6d69ea9908edb2a98a6e0d8b897845569210
MD5 hash:
0a79540e721aef54d3646ecaca4a2550
SHA1 hash:
2586fad862065f0904914c3c20f8290702ca000f
SH256 hash:
4a813cad86b88b584d7d954da4c9fe2d8b1dbf0e23e992ecd966325889cbdd1b
MD5 hash:
91d14a620c8a668ade0d8851eb07518d
SHA1 hash:
53f0f2b2b0a34e68137439db3dee22353a5fc47a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_SUSPICIOUS_ClearWinLogs
Author:ditekSHen
Description:Detects executables containing commands for clearing Windows Event Logs
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:INDICATOR_SUSPICIOUS_GENRansomware
Author:ditekSHen
Description:Detects command variations typically used by ransomware
Rule name:INDICATOR_SUSPICIOUS_USNDeleteJournal
Author:ditekSHen
Description:Detects executables containing anti-forensic artifacts of deleting USN change journal. Observed in ransomware
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:upx_largefile
Author:k3nr9
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mimic

Executable exe eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments