MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efab45e445f7f3895ae26f54819eb30e7fdbe0b289e12d8f7c077f895efbe2d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 5 File information Comments

SHA256 hash: efab45e445f7f3895ae26f54819eb30e7fdbe0b289e12d8f7c077f895efbe2d4
SHA3-384 hash: 3dae9800800978fd58c5789c46dbcd5a3393a8626498c9b8b05a484aba74f508f8b416553e385496ff72b471b9ce4e4b
SHA1 hash: ea158854465633fe3594f0fb786fd6f8313ad55b
MD5 hash: 80b54fbeaccf1f1aeb131c56bf3b42c1
humanhash: crazy-carolina-eighteen-california
File name:Protection.Agent.v2.exe
Download: download sample
File size:1'511'936 bytes
First seen:2026-07-19 14:37:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'121 x AgentTesla, 20'132 x Formbook, 12'360 x SnakeKeylogger)
ssdeep 24576:iyN2MetPvstcZQ0ZJn9zt8Wkm+b1DPNmbWtVYhekYiJirT1dbSpX96r70Gee7Tt:Fotht9z2Wkmm1obuV3IJirT1INZyTt
TLSH T19A6512C9761072EFC52BD47089A66CA9F7057C7A872B4947C0173DAD9A7C88BDF180B2
TrID 20.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
19.8% (.EXE) Win64 Executable (generic) (6522/11/2)
15.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4504/4/1)
6.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon 04eeb2b8e8f09e00
Reporter Anonymous
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Protection.Agent.v2.exe
Verdict:
Malicious activity
Analysis date:
2026-07-19 14:34:41 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
ransomware virus msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the Windows subdirectories
Enabling the 'hidden' option for recently created files
Creating a process from a recently created file
Creating a file
Setting a keyboard event handler
Сreating synchronization primitives
Creating a file in the %temp% directory
Searching for synchronization primitives
Deleting a recently created file
Searching for the window
Deleting a system file
Launching a process
Modifying a system file
Unauthorized injection to a recently created process
Changing the Windows explorer settings
Blocking a possibility to launch for the Windows Task Manager (taskmgr)
Blocking the User Account Control
Blocking a possibility to launch for cmd.exe command interpreter
Forced shutdown of a system process
Deleting volume shadow copies
Enabling autorun
Forced shutdown of a browser
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 masquerade obfuscated obfuscated packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-19T11:47:00Z UTC
Last seen:
2026-07-21T01:23:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Spy.MSIL.Stealer.gen Trojan.Win32.Diztakun.sb Trojan.Win32.DelShad.sb Trojan.Win32.Agent.sb
Verdict:
inconclusive
YARA:
7 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.99 Win 32 Exe x86
Threat name:
Win32.Trojan.Msilheracles
Status:
Malicious
First seen:
2026-07-19 14:38:36 UTC
File Type:
PE (.Net Exe)
Extracted files:
16
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
GenericRansomware
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion execution impact persistence ransomware trojan
Behaviour
Interacts with shadow copies
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
Drops file in Windows directory
Checks whether UAC is enabled
Enumerates connected drives
Modifies boot configuration data using bcdedit
Checks computer location settings
Executes dropped EXE
Disables RegEdit via registry modification
Disables Task Manager via registry modification
Disables use of System Restore points
Event Triggered Execution: Image File Execution Options Injection
Overwrites deleted data with Cipher tool
Deletes shadow copies
Modifies WinLogon for persistence
UAC bypass
Unpacked files
SH256 hash:
efab45e445f7f3895ae26f54819eb30e7fdbe0b289e12d8f7c077f895efbe2d4
MD5 hash:
80b54fbeaccf1f1aeb131c56bf3b42c1
SHA1 hash:
ea158854465633fe3594f0fb786fd6f8313ad55b
SH256 hash:
19f9b23e001f5caed1694a4649f88700ba7d03e32773745a9901e0f15181491f
MD5 hash:
d196a470275e9a741937835f3154cb83
SHA1 hash:
0023cd07ee5c1ec305056b6189a36d5cc49ef0eb
SH256 hash:
b1e22e1b886c79e7dce2732df6718ac0f41b96e81a1f997d9d3d57f0eb31d632
MD5 hash:
4b1abf7f72e18f2828017c21f09aab23
SHA1 hash:
0b91da66851c245b26f021953a6d7827c935be47
SH256 hash:
a6a89ce7b5c2b87c5d8b795360c491f07b6dff876af867c48c344136e3e549f0
MD5 hash:
d7e38b825fc12ef90ca600481d87482b
SHA1 hash:
2abe1904db0157bc4bdf9bf54b172fee5d678b34
SH256 hash:
829de5bc9fa297e9f02eb25f74ebf26d72c56e18f81560af81e6aeb7ffd38b80
MD5 hash:
3a61dc325a2970bd65a387c5408f8836
SHA1 hash:
2d23d9003b469b4650af47a681cf0610ca6c4b29
SH256 hash:
3cc363dd133641724ec9c97d691cc0d4dee922e12e0fcb7e153dd046d647e4e6
MD5 hash:
56c830e2309c2422df1a89f1816cb136
SHA1 hash:
8bd326af557f5f570cb5d2de1fbc2c3e1a1109b8
SH256 hash:
5af945577cf20d222d940339e4fe4ea2bb636d724ec701ec3ecde8e14faa9be5
MD5 hash:
8fc1d7bd37521ccecbba6b309df0f6a6
SHA1 hash:
e519d4f43d4de9447e4490b011a1a3f5bb0541ea
SH256 hash:
b6875225aec8247ecfd274cd3fe229ce2130ccae2673779b0d48da65cd1ee24d
MD5 hash:
d96859a25773034f49c992e668238fc5
SHA1 hash:
4b2bffb418b977c653f00c32bf8a2cb0d5c63154
SH256 hash:
17ff04e51fd3f00fe198802f5ef37482b0c4f02da201bb15933201f37ca406bd
MD5 hash:
64df7bbf06c42beaf5704e0043f118c8
SHA1 hash:
f5d432399d1ec4ec56cd21e1d942f87dc5f68748
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments