🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash b4ff59be95361d56347d381ffa917a5e583937b5c854b243e466d9d8f5bc2990.

Database Entry


IOC ID:1915566
IOC: b4ff59be95361d56347d381ffa917a5e583937b5c854b243e466d9d8f5bc2990
IOC Type :sha256_hash
Threat Type :payload
Malware: Hades
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-09-12 07:28:48 UTC
Last seen:2026-09-13 18:51:00 UTC
UUID:30cdec53-ae79-11f1-b569-42010aa4000a
Reporter devmihaylov
Reward 5 credits from ThreatFox
Tags:Discord Electron Hades NSIS RAT stealer turkey wallet
Reference: https://x.com/devmihaylov/status/2098669836414984398

Avatar
devmihaylov
Togethers.exe, 124,525,689 bytes, unsigned NSIS installer carrying an Electron app with bytenode compiled logic. Reports to hellodcuser.com with the x-license-key, x-tg-id, x-hwid header triple.