🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash f3ef4663e909e2545d25bdd0edc7ba4f88d197760921ca23e7dededf7326aa8e.

Database Entry


IOC ID:1817267
IOC: f3ef4663e909e2545d25bdd0edc7ba4f88d197760921ca23e7dededf7326aa8e
IOC Type :sha256_hash
Threat Type :payload
Malware: Satacom
Malware alias:CurlyGate, LegionLoader, RobotDropper
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-05-22 13:32:09 UTC
Last seen:never
UUID:58e11e37-55e2-11f1-b930-42010aa4000a
Reporter andrewpetrus
Reward 5 credits from ThreatFox
Tags:curlygate LegionLoader Satacom
Reference: https://x.com/AndrewPetrus/status/2057813304727552345?s=20

Avatar
andrewpetrus
Stage 1: 4e286cd901813a5f80411e417fb5defe25ff9af00706e68509392f6e75cc3908
Stage 2: f3ef4663e909e2545d25bdd0edc7ba4f88d197760921ca23e7dededf7326aa8e