faceshop.io_hyber.exe

Classification: Malicious

faceshop.io_hyber.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-03. IoC context and downloadable threat intel on Maltiverse.

Detection summary

  • 0 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 2 contacted hosts
  • 9 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-09-03 00:45:07 2026-09-03 00:45:07 malicious-activity
Suspicious Sample Triage 2026-09-02 23:58:05 2026-09-02 23:58:05 anomalous-activity

Tags

evasive ransomware defense_evasion discovery evasion execution impact persistence privilege_escalation spyware stealer trojan

Sample information

Filenames
faceshop.io_hyber.exe, sample-3a92f302f5b3.exe
File type
PE32 executable for MS Windows 4.00 (GUI), Intel i ...
MD5
024e671fad78e7c35c8e60871799948a
SHA-1
2ae7cc25ceb9f99d9a003f0068fae21efb5c9638
SHA-256
3a92f302f5b36e0e8c816b431a5c62f2274351085af3db6b02525353866364fb
First indexed
2026-09-02 23:58:05
Last updated
2026-09-03 00:57:46

Network contacts

85.17.56.34 94.102.61.78

DNS requests

emotet.com faceshop.io i2p2.de malware.wicar.org ryuk.com torproject.org trickbot.com wannacry-decryptor.com www.zeltser.com