| File name: | loader.exe |
| Full analysis: | https://app.any.run/tasks/048c7dda-1bc3-44eb-907e-1dff096d79af |
| Verdict: | Malicious activity |
| Threats: | DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes. |
| Analysis date: | March 15, 2026, 05:56:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 7 sections |
| MD5: | 79EE13169B4947F2D9354321A225A6A5 |
| SHA1: | 533FA623E061056707BB3170DD17B0B19E30D32E |
| SHA256: | 5DB5FCF4906F2826BC93A5D0AEDAB2031B45032B1E63A363EEB49CB0A07A4E08 |
| SSDEEP: | 1536:OOns2mVYS8ALOwa430v34Fco8DHvoEBVjbMzxTn4nx/:wdVJXRk46ouvNBViRn4nR |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2026:03:15 05:56:34+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 2.46 |
| CodeSize: | 2048 |
| InitializedDataSize: | 76800 |
| UninitializedDataSize: | 512 |
| EntryPoint: | 0x1000 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3580 | "C:\Users\admin\Desktop\loader.exe" | C:\Users\admin\Desktop\loader.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_100.png | binary | |
MD5:8C236529CA60511F2DFFCF7E72E19FA4 | SHA256:343649FB7CD7F737E9AC53CADECE6DC47414052AB8F3E41DBCC302F240F3A3FF | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_200.png | binary | |
MD5:4E72BCAC926E6700AD943822B16B48E9 | SHA256:76061FE2C8A3E834FE0168F426AA711921261924BEC84C94A904F070A80B8AE5 | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gray_button_200.png.rams0n | binary | |
MD5:EFE73B8730CF3882E7E0F4A8F6498766 | SHA256:9D77DCB9B1050D0F6A986BB3CF20DC7C65DD359D47950A01624FE7454FBC3DFE | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\close_200.png | binary | |
MD5:A867B705791D14DA20C2B091F4D1A898 | SHA256:4DBC3E0B0B1B6E109A22A962D31EE9BAEDF3FA95994B5E42A5493A588E3B5CE9 | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\info_icon_100.png.rams0n | binary | |
MD5:0F4B54FAAAA3D92667EE2316E9261617 | SHA256:A202A53E67EE3528B963C7994E00ED867E9D1A51829C3D0925D7DEF86DB34A3E | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\info_icon_100.png | binary | |
MD5:0F4B54FAAAA3D92667EE2316E9261617 | SHA256:A202A53E67EE3528B963C7994E00ED867E9D1A51829C3D0925D7DEF86DB34A3E | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\close_200.png.rams0n | binary | |
MD5:A867B705791D14DA20C2B091F4D1A898 | SHA256:4DBC3E0B0B1B6E109A22A962D31EE9BAEDF3FA95994B5E42A5493A588E3B5CE9 | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gray_button_200.png | binary | |
MD5:EFE73B8730CF3882E7E0F4A8F6498766 | SHA256:9D77DCB9B1050D0F6A986BB3CF20DC7C65DD359D47950A01624FE7454FBC3DFE | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_125.png | binary | |
MD5:539292C2D935F724C1930F2F89E6E89F | SHA256:E09301789C78262B0C494D3B9B0B7BB2DBC5E042274FB9D815184D52003F7E66 | |||
| 3580 | loader.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_100.png.rams0n | binary | |
MD5:8C236529CA60511F2DFFCF7E72E19FA4 | SHA256:343649FB7CD7F737E9AC53CADECE6DC47414052AB8F3E41DBCC302F240F3A3FF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
1092 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |