MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b09e1ef7e44680e2fdd5909dbae73c46ad9d4d007f9ef077acfa102a613f908. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 1b09e1ef7e44680e2fdd5909dbae73c46ad9d4d007f9ef077acfa102a613f908
SHA3-384 hash: 411aa53d8767f40651ca41e41781c5b93a6feb2992b599c01dc01d0f0f3945f47c67cf94eaa20b1b7f2d885b06b6f6c8
SHA1 hash: b1684ae28b3f3f14b984e0a8849b5f82c7aba6bf
MD5 hash: 9998b70b29e9898618588f8fbc450dc3
humanhash: equal-hydrogen-october-gee
File name:SecuriteInfo.com.Atros7.BHRE.22933.1024
Download: download sample
File size:1'117'696 bytes
First seen:2020-03-18 10:04:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 35bfee634c7dac22726f7ae42156fd5a
ssdeep 24576:lvdSuGEeNqGed+HmomnY/g3EGtjlwMnU0e5cxitwZKHAeGVFoFRDOR:l19reNqGeoHmD6qEaZwMkcxitSKSzcRk
Threatray 1 similar samples on MalwareBazaar
TLSH D9352356EA1CB185F677497E50CBF4430E2FF8812D45CECE98226B9E5426D3DF9A2038
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-03-19 03:56:18 UTC
AV detection:
27 of 31 (87.10%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:suspicious_packer_section
Author:@j0sm1
Description:The packer/protector section names/keywords
Reference:http://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyA

Comments