MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f103f152e4d1e17975482ef7b7fd05e798055822efa3756203f526e1fbc93fb5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HijackLoader


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: f103f152e4d1e17975482ef7b7fd05e798055822efa3756203f526e1fbc93fb5
SHA3-384 hash: 47b253acd5a6ca474e8e5b3ef0b6f0b2ecd1aa7ae4f4ed347e26df64fb087ec94bb789016d32abfb43f26da4c55319e6
SHA1 hash: 96c04cf5ed8238a60a0ae8ceeb7d19cde1bf7e50
MD5 hash: 1f1908d1cef917b8b122b992c9a4e6df
humanhash: yankee-four-romeo-michigan
File name:f103f152e4d1e17975482ef7b7fd05e798055822efa3756203f526e1fbc93fb5
Download: download sample
Signature HijackLoader
File size:3'730'992 bytes
First seen:2026-03-25 08:36:24 UTC
Last seen:2026-03-25 09:52:38 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 20dd26497880c05caed9305b3c8b9109 (31 x Adware.Auslogics, 29 x HijackLoader, 5 x Adware.IObit)
ssdeep 98304:lELZOWzgmIcBXR+Vx0SsUUdNYqg5o6B6WSuR:OdcqBo8fUUdQa6kfuR
TLSH T1CD062353B2D74073F2915A3AC859D2389D6237BC29F652112CF4F99DB8BA3814E37362
TrID 76.2% (.EXE) Inno Setup installer (107240/4/30)
10.0% (.EXE) Win32 Executable Delphi generic (14182/79/4)
4.6% (.EXE) Win64 Executable (generic) (6522/11/2)
3.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.4% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon b2e8ccaab2d46992 (1 x HijackLoader)
Reporter JAMESWT_WT
Tags:exe Guangzhou-Duqing-Technology-Co-Ltd HIjackLoader signed

Code Signing Certificate

Organisation:广州杜倾科技有限公司
Issuer:Certum Extended Validation Code Signing 2021 CA
Algorithm:sha256WithRSAEncryption
Valid from:2026-01-29T08:37:07Z
Valid to:2027-01-29T08:37:06Z
Serial number: 1585c2edd17bb80bc7de15448cf4792d
Intelligence: 4 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 9ff8533b268267f1eaa008c05a74f06cc92198e813f2ea9e0593bdc61e4af6e0
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
151
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
FVBLIHPG.exe
Verdict:
Malicious activity
Analysis date:
2026-03-10 18:28:15 UTC
Tags:
hijackloader loader stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
dropper crypt sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Creating a file in the %AppData% subdirectories
Using the Windows Management Instrumentation requests
Unauthorized injection to a recently created process by context flags manipulation
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
embarcadero_delphi fingerprint inno installer installer installer-heuristic packed revoked-cert signed
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Hijackloader
Status:
Malicious
First seen:
2026-03-10 18:44:24 UTC
File Type:
PE (Exe)
Extracted files:
61
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
hijackloader
Similar samples:
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader discovery installer loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Detects HijackLoader (aka IDAT Loader)
HijackLoader, IDAT loader, Ghostulse,
Hijackloader family
Unpacked files
SH256 hash:
f103f152e4d1e17975482ef7b7fd05e798055822efa3756203f526e1fbc93fb5
MD5 hash:
1f1908d1cef917b8b122b992c9a4e6df
SHA1 hash:
96c04cf5ed8238a60a0ae8ceeb7d19cde1bf7e50
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
SH256 hash:
e2a47f5ac2b38ae94e879d568b420b9e5e015c6bfd8be19db81ec127204941f6
MD5 hash:
7e75694dc6867a74ae54a93121bbbb7d
SHA1 hash:
3cb3b2f8f29b446af0f3f4204b9e221d1912aae6
SH256 hash:
44b8e6a310564338968158a1ed88c8535dece20acb06c5e22d87953c261dfed0
MD5 hash:
9c8886759e736d3f27674e0fff63d40a
SHA1 hash:
ceff6a7b106c3262d9e8496d2ab319821b100541
SH256 hash:
c9b73d8e971dbe704108ec39c8e04a5cba9729aef56fd7179e5f8d4e59644d05
MD5 hash:
3ec95cbbbcfd1ed09c317c240d1e1a9e
SHA1 hash:
dba7b79ee953087e88623c2d0afee0513837d10e
SH256 hash:
08a93ad91061aeda02121ae6a4fc9ec024f612e39626c615fd5f3765957608a4
MD5 hash:
2e259afb699d02eecfa0817e791e3324
SHA1 hash:
3873b36b6b1257dfa6543124383e932d553126a4
SH256 hash:
96011a7fd70f795750b647d17d9bcc0c997873eee28ad4ee749b12f25a5b214c
MD5 hash:
c4013a47783292ede97b4fd191634acb
SHA1 hash:
620d6c114e8b3655974d07765f458175d5ff3c1a
SH256 hash:
a6edb3fb6d21dd461da3767a7995034e208f7d6b08997f6cf7ee7b0ea833a8f0
MD5 hash:
cabb58bb5694f8b8269a73172c85b717
SHA1 hash:
9ed583c56385fed8e5e0757ddb2fdf025f96c807
SH256 hash:
68bee500e0080f21c003126e73b6d07804d23ac98b2376a8b76c26297d467abe
MD5 hash:
d4dae7149d6e4dab65ac554e55868e3b
SHA1 hash:
b3bea0a0a1f0a6f251bcf6a730a97acc933f269a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments