🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc16a364530103595b8d36d6c3e7f00a08bf5783c6860bf63bcdbeb90b6c78f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 15


Intelligence 15 IOCs YARA 13 File information Comments

SHA256 hash: fc16a364530103595b8d36d6c3e7f00a08bf5783c6860bf63bcdbeb90b6c78f8
SHA3-384 hash: ce114ee38de1f5cf3dac72a8921b8172777489c587b031b56dec0e04320decf97aa4672d41c2f4478112ff3fbb107e8e
SHA1 hash: 08e39fc3da82982d870856f46db8695af30b9d75
MD5 hash: c7573a76290ba4fccb1edeb186e12071
humanhash: charlie-uranus-thirteen-black
File name:shark.exe
Download: download sample
File size:13'240'408 bytes
First seen:2025-05-12 22:35:30 UTC
Last seen:2025-05-13 02:27:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7f0e6c8549a2ece8abcacfac06e9633c
ssdeep 98304:ghHP6kvqv6Gcbs2uOLPlexDwGEwpDDNXiYGQbalZLCwpokCFCxJD9LKho:g1P6wEBObleF3DBLLo
Threatray 271 similar samples on MalwareBazaar
TLSH T1FFD60922F2A48A35C0DE473A509F47118335411B4F97A78702E4A9BDFE9E2A12F7674F
TrID 58.9% (.EXE) Inno Setup installer (107240/4/30)
22.8% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
5.7% (.EXE) Win64 Executable (generic) (10522/11/4)
5.4% (.EXE) DOS Borland compiled Executable (generic) (10000/1/2)
2.4% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon f0f8c9d9c9e9f0d0 (1 x DCRat)
Reporter skocherhan
Tags:CTY-TNHH-MOT-THANH-VIEN-THUONG-MAI-DICH-VU-TAM-TAI exe signed

Code Signing Certificate

Organisation:CTY TNHH MOT THANH VIEN THUONG MAI DICH VU TAM TAI
Issuer:DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Algorithm:sha256WithRSAEncryption
Valid from:2025-04-29T00:00:00Z
Valid to:2026-04-28T23:59:59Z
Serial number: 096473e3991014691a73038c059a866e
Intelligence: 4 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 504f4ea2606c53dab51da1dd7a060936bdb42f786dc447a821692b6349940790
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
skocherhan
https://batmanuniver.com/shark.exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
581
Origin country :
GB GB
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
program.exe
Verdict:
Malicious activity
Analysis date:
2025-05-12 20:00:54 UTC
Tags:
auto-startup ims-api generic golang ms-smartcard uac github rdp remote rdpwrap rmm-tool telegram

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
dropper delphi shell spawn
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
Creating a file in the %temp% directory
Launching a service
Running batch commands
Creating a process with a hidden window
Creating a file
Loading a system driver
Launching the process to interact with network services
DNS request
Launching a process
Connection attempt
Sending a custom TCP request
Launching the process to change the firewall settings
Creating a file in the Windows subdirectories
Sending an HTTP GET request
Creating a file in the Program Files subdirectories
Searching for the window
Enabling autorun for a service
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context apt cmd embarcadero_delphi fingerprint keylogger lolbin netsh overlay packed packed rdpwrap remote remoteadmin signed
Verdict:
Malicious
Labled as:
RDPWrap.A potentially unsafe application
Result
Threat name:
RDPWrap Tool
Detection:
malicious
Classification:
spre.troj.evad
Score:
66 / 100
Signature
Allows multiple concurrent remote connection
Enables remote desktop connection
Modifies security policies related information
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: RDP Sensitive Settings Changed
Sigma detected: Suspicious Add User to Remote Desktop Users Group
Uses netsh to modify the Windows network and firewall settings
Yara detected RDPWrap Tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1688457 Sample: shark.exe Startdate: 13/05/2025 Architecture: WINDOWS Score: 66 45 raw.githubusercontent.com 2->45 49 Multi AV Scanner detection for dropped file 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 Sigma detected: Suspicious Add User to Remote Desktop Users Group 2->53 55 2 other signatures 2->55 9 shark.exe 4 18 2->9         started        14 rdpdr.sys 8 2->14         started        16 rdpvideominiport.sys 4 2->16         started        18 tsusbhub.sys 3 2->18         started        signatures3 process4 dnsIp5 47 raw.githubusercontent.com 185.199.111.133, 443, 49718 FASTLYUS Netherlands 9->47 39 C:\Windows\System32\rfxvmt.dll, PE32+ 9->39 dropped 41 C:\Program Files\RDP Wrapper\rdpwrap.dll, PE32+ 9->41 dropped 43 C:\Users\user\...\enable_rdp_config.bat, DOS 9->43 dropped 61 Allows multiple concurrent remote connection 9->61 63 Enables remote desktop connection 9->63 65 Modifies security policies related information 9->65 20 cmd.exe 1 9->20         started        23 cmd.exe 1 9->23         started        file6 signatures7 process8 signatures9 57 Uses netsh to modify the Windows network and firewall settings 20->57 59 Modifies the windows firewall 20->59 25 net.exe 1 20->25         started        27 netsh.exe 43 2 20->27         started        29 conhost.exe 20->29         started        31 net.exe 1 23->31         started        33 conhost.exe 23->33         started        process10 process11 35 net1.exe 1 25->35         started        37 net1.exe 1 31->37         started       
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2025-05-12 20:11:01 UTC
File Type:
PE (Exe)
Extracted files:
58
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery lateral_movement persistence privilege_escalation
Behaviour
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Loads dropped DLL
Drops file in System32 directory
Legitimate hosting services abused for malware hosting/C2
Modifies WinLogon
Modifies Windows Firewall
Allows Network login with blank passwords
Server Software Component: Terminal Services DLL
Remote Service Session Hijacking: RDP Hijacking
Verdict:
Malicious
Tags:
red_team_tool Win.Malware.Ursu-9937395-0
YARA:
RDPWrap
Unpacked files
SH256 hash:
fc16a364530103595b8d36d6c3e7f00a08bf5783c6860bf63bcdbeb90b6c78f8
MD5 hash:
c7573a76290ba4fccb1edeb186e12071
SHA1 hash:
08e39fc3da82982d870856f46db8695af30b9d75
Detections:
RDPWrap
SH256 hash:
2f33ed67124a2225104726cb59f001e5ff4d78b0d88a650ced997890b515a73b
MD5 hash:
51b15fc8de1a07851f648ffe4362e5ca
SHA1 hash:
b8215e0a97424eff245eaf196ed4fccd154723b6
SH256 hash:
63fb201040002775e6ef6f836a8f0f4d94324fc299c0f9bc1f17a97c6bb24552
MD5 hash:
5505592313b74f2e2c8727837750f66d
SHA1 hash:
d0394cf350090ba4fc68c7e12fd806881b0c42e0
SH256 hash:
4c19d053751a68b30c045119642964268659bf79bd066046c32ddb875ec339eb
MD5 hash:
b52ac2b928342ee016739834af802beb
SHA1 hash:
1d4d62475d6ab667fdbc68a46177b7ae01c2ddeb
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_Lazarus_Loader_Dec_2020_1
Author:Arkbird_SOLG
Description:Detect loader used by Lazarus group in december 2020
Reference:Internal Research
Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
Rule name:Borland
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Mimikatz_Generic
Author:Still
Description:attempts to match all variants of Mimikatz
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RDPWrap
Author:@bartblaze
Description:Identifies RDP Wrapper, sometimes used by attackers to maintain persistence.
Reference:https://github.com/stascorp/rdpwrap
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Executable exe fc16a364530103595b8d36d6c3e7f00a08bf5783c6860bf63bcdbeb90b6c78f8

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::ConvertStringSidToSidW
advapi32.dll::SetEntriesInAclW
advapi32.dll::SetNamedSecurityInfoW
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
MULTIMEDIA_APICan Play Multimediagdi32.dll::StretchDIBits
SECURITY_BASE_APIUses Security Base APIadvapi32.dll::AdjustTokenPrivileges
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CreateProcessW
advapi32.dll::OpenProcessToken
kernel32.dll::OpenProcess
wininet.dll::InternetCloseHandle
kernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::TerminateProcess
kernel32.dll::LoadLibraryA
kernel32.dll::LoadLibraryExW
kernel32.dll::LoadLibraryW
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoW
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::GetConsoleOutputCP
kernel32.dll::GetConsoleCP
kernel32.dll::GetConsoleWindow
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateDirectoryW
kernel32.dll::CreateFileW
kernel32.dll::GetFileAttributesW
kernel32.dll::FindFirstFileW
version.dll::GetFileVersionInfoSizeW
version.dll::GetFileVersionInfoW
WIN_BASE_USER_APIRetrieves Account Informationadvapi32.dll::GetUserNameW
advapi32.dll::LookupPrivilegeValueW
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegConnectRegistryW
advapi32.dll::RegCreateKeyExW
advapi32.dll::RegDeleteKeyW
advapi32.dll::RegLoadKeyW
advapi32.dll::RegOpenKeyExW
advapi32.dll::RegQueryInfoKeyW
WIN_SVC_APICan Manipulate Windows Servicesadvapi32.dll::ChangeServiceConfigW
advapi32.dll::OpenSCManagerW
advapi32.dll::OpenServiceW
advapi32.dll::QueryServiceConfigW
advapi32.dll::StartServiceW
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::EmptyClipboard
user32.dll::FindWindowExW
user32.dll::FindWindowW
user32.dll::OpenClipboard

Comments