🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f98630a660fe803dcd45683a7bda303c22e2188e6ebcff6bbc4dd022b3b26cfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 6 File information Comments

SHA256 hash: f98630a660fe803dcd45683a7bda303c22e2188e6ebcff6bbc4dd022b3b26cfa
SHA3-384 hash: e71399f4d8908a56c4bbb83d8b1b07984a80d0c42ac6dc777762e59788bdb4061129004b8216c77313f636c037194f86
SHA1 hash: eb2cbd3b1178c37eaa3a03fd09702aa4c8281092
MD5 hash: 96addc058726aae89cbe6beb14416499
humanhash: skylark-lemon-bacon-mountain
File name:f98630a660fe803dcd45683a7bda303c22e2188e6ebcff6bbc4dd022b3b26cfa.bin
Download: download sample
File size:27'441 bytes
First seen:2026-09-30 06:12:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:v4FcZqc0pCe0zLMai34tqet7TPwqSyI8NsdFy:gm4wvzL2MvTwq6BdFy
TLSH T187C2E1D634C5E1A6D9A3080766A7ED427CD3E6D07B13DCC6D3017A481A806FB96C90F7
Magika zip
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Krotten.exe
File size:54'569 bytes
SHA256 hash: e79f164ccc75a5d5c032b4c5a96d6ad7604faffb28afe77bc29b9173fa3543e4
MD5 hash: 87ccd6f4ec0e6b706d65550f90b0e3c7
MIME type:application/x-dosexec
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
dropper evasive explorer keylogger lolbin masm overlay packer ransomware reconnaissance rundll32
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-22T17:37:00Z UTC
Last seen:
2026-09-25T19:49:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.Krotten
Status:
Malicious
First seen:
2026-09-22 15:58:07 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
32 of 36 (88.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware defense_evasion discovery persistence spyware stealer
Behaviour
Modifies Control Panel
Modifies Internet Explorer settings
Modifies Internet Explorer start page
Modifies registry class
Suspicious use of AdjustPrivilegeToken
System policy modification
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Modifies WinLogon
Disables RegEdit via registry modification
Disables Task Manager via registry modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Win_Clipboard_Clipper_Thengavar
Author:Thengavar
Description:Detects malware manipulating the Windows clipboard for clipping or crypto stealing attacks
Rule name:WIN_Clipper_Unknown_ClipboardHijack
Author:Marjoriefort
Description:DLL clipper (detournement presse-papiers crypto) : API clipboard completes + DLL compacte
Reference:misses_archive 569 / cluster 282 DLL x 15360 o

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip f98630a660fe803dcd45683a7bda303c22e2188e6ebcff6bbc4dd022b3b26cfa

(this sample)

  
Delivery method
Distributed via web download

Comments