MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa0af45e17e3bc6e05d025f34ac37005b4914014fb24bec2fd077f2a197fbc78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



KongTuke


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: fa0af45e17e3bc6e05d025f34ac37005b4914014fb24bec2fd077f2a197fbc78
SHA3-384 hash: 4a18e5c97bc2ab88a3e1ad5f53703b9bd94186b6ccb562e7b1524c15e17d4094358b8ccbd4c11e9bc25cea6773891830
SHA1 hash: 5ab025945f9f21cb7065b5df140fae41b0f8242a
MD5 hash: 60a372d1279eafd56631c47471992e49
humanhash: london-zulu-spring-august
File name:d
Download: download sample
Signature KongTuke
File size:1'075'200 bytes
First seen:2026-06-01 14:07:55 UTC
Last seen:Never
File type: tar
MIME type:application/x-tar
ssdeep 24576:Wihx1hQVmTTY8cBChpkFCWiDgM3wWRO9aQ7ksk6ahymU8n0T94W:Wihx12VmnxhpwrawENOijUyM
TLSH T10F355C5AEBF64CE9D8E2C0B045B72310EA3039D547505AFF566886282B2B7C0B73D779
TrID 62.9% (.TAR/USTAR) TAR - Tape ARchive (POSIX) (17/3)
37.0% (.TAR) TAR - Tape ARchive (file) (10/3)
Magika tar
Reporter monitorsg
Tags:Kongtuke tar


Avatar
monitorsg
hXXps://marqueq[.]lol/file.js (ClickFucker) --> hXXps://marqueq[.]lol/api/v1/session (token) --> hXXps://marqueq[.]lol/api/v1/verify (gateway) --> hXXps://marqueq[.]lol/api/v1/status (clipboard) --> hXXps://qmogvdgy[.]icu/d (tar)

Intelligence


File Origin
# of uploads :
1
# of downloads :
14
Origin country :
US US
File Archive Information

This file archive contains 14 file(s), sorted by their relevance:

File name:CiscoSparkCrypto.dll
File size:40'960 bytes
SHA256 hash: f28192652a4f03f88c50a330829e1981d44d2bc7b8ba82cd104ed7c3d0801bee
MD5 hash: 8089d5457c41d210c5ccd9ae4bdd05a1
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkSync.dll
File size:51'200 bytes
SHA256 hash: ca212a330f9d6d0320e3b327ca7e1c30b773baf8ec5705a62030fc6968b54686
MD5 hash: f32a54b9bb5f6780542fc92d809884ff
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkScheduler.dll
File size:18'432 bytes
SHA256 hash: 0923ebfa8a46d79dc5284dbc93be5dfa887114782a5cbf23170204eaa09ef712
MD5 hash: 5fdd4f21757062260d897b27ffbbb118
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkDiagnostics.dll
File size:9'728 bytes
SHA256 hash: 1c7bee0fbc8871079970db80af0b73bef9bc743a322c0db2801e7c01031eb354
MD5 hash: 2e102d1d09ef6694e8541fdd94edece6
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoCollabHost.exe
File size:396'000 bytes
SHA256 hash: c70b5fada48ce5e4ade6b111bc1b1d38e177c553798655227bd87f2ff2532fe8
MD5 hash: 60b921c0dd1f37474d49685a6b6bf0bb
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkLauncher.dll
File size:35'840 bytes
SHA256 hash: 1aa0acd867e7b7786457abc9257d7186bb05bab87747784b26f90c0289169f69
MD5 hash: 2c3dfae868edde1aba3abea2da3c214a
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkCompliance.dll
File size:66'560 bytes
SHA256 hash: 3d6188b2aff430184bfb9aebac10bca755fb407520203ac1a9737dc6f07a6f62
MD5 hash: 09a8d92c55bc5c5f5f1b19a7282b04c8
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkCore.dll
File size:78'336 bytes
SHA256 hash: b447412d2ca4c82957f14f34affbc0c4836611099bd83890e110ed7a16b118d9
MD5 hash: d0a104a42726eed9504d8e0ba7b2218d
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkServices.dll
File size:214'016 bytes
SHA256 hash: 3d0e4316449e45cd9783e684cd3beca9fe555ef5a325da71ef3b51a67c3bd39d
MD5 hash: 397db03a33f225e45d70a6e9cf7d0423
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkMonitor.dll
File size:23'040 bytes
SHA256 hash: d59a4c3b2283efe642a361e680564f5ac515803b5b237c85cf25f019b7cc005e
MD5 hash: 5e115f39cfbb8c1863fe020026c8af33
MIME type:application/x-dosexec
Signature KongTuke
File name:wintrust.dll
File size:20'992 bytes
SHA256 hash: cdfae9f1d9702545972c1aee9e349cd3df4e6be8550f5d35ca3c508c6c9a7dc7
MD5 hash: 64d6881580746c1b575b06dd243924fd
MIME type:application/x-dosexec
Signature KongTuke
File name:2
File size:762 bytes
SHA256 hash: 1fcba8090d0bc5e80b9537a0a3c6a611d427a0da082a693af2947f610a83f4d2
MD5 hash: 44da4ad3acba07686b7789f48a8d6c48
MIME type:text/plain
Signature KongTuke
File name:CiscoSparkRuntime.dll
File size:36'352 bytes
SHA256 hash: 71f8961e8ac848070e1a1e7551b0939de4fc858ea94a0e579f8e2361f2fba157
MD5 hash: 92c094bddd047d591ca80c1fca52c9c4
MIME type:application/x-dosexec
Signature KongTuke
File name:CiscoSparkBridge.dll
File size:74'240 bytes
SHA256 hash: 3d86cd1def4c9f534b7b77c9f62a0061a26f10f576e00fa02ab396161196c92e
MD5 hash: 7a9efa5690b386d3c381980f08d73d47
MIME type:application/x-dosexec
Signature KongTuke
Vendor Threat Intelligence
No detections
Gathering data
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-06-01 15:12:51 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion spyware trojan
Behaviour
Modifies system certificate store
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:meth_stackstrings
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

KongTuke

tar fa0af45e17e3bc6e05d025f34ac37005b4914014fb24bec2fd077f2a197fbc78

(this sample)

  
Delivery method
Distributed via web download

Comments