MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4eb372dc146535028ffa1c88b7a6f0c7ce3a462b9dd53e1f7acdb61545bdfeeb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 4eb372dc146535028ffa1c88b7a6f0c7ce3a462b9dd53e1f7acdb61545bdfeeb
SHA3-384 hash: ef5818272b6c2e6166e9ea289b9220e30724badfad95be2042ea9b2940c3a931eaf52c62a662ae9ec0e7ea46f5e63002
SHA1 hash: 4db4babe1385d1fd05021e68646b3ddf4ec4cfc9
MD5 hash: 8038c006296c2d07c47f71cf22730881
humanhash: beryllium-sink-virginia-wolfram
File name:4eb372dc146535028ffa1c88b7a6f0c7ce3a462b9dd53e1f7acdb61545bdfeeb
Download: download sample
File size:4'417'716 bytes
First seen:2020-06-03 09:18:19 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dbbc718f7f0ca351f7a0e645fde2dbea
ssdeep 98304:3+I3L/wlG4UZej0jvy5SbWf+YFCbJBAUZLs2KO:3HPvyQaf+HbJVDKO
Threatray 58 similar samples on MalwareBazaar
TLSH B116D103F2818472D81719700C77673A6A36FF116F258A93B794FE6D1D732E2973628A
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vmpbad
Status:
Malicious
First seen:
2020-06-03 17:37:39 UTC
AV detection:
42 of 47 (89.36%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious behavior: RenamesItself
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments