MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ed0051747d0d5fbf4273b02e7267a257a82217c4b474117ea853014218b2b18. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6ed0051747d0d5fbf4273b02e7267a257a82217c4b474117ea853014218b2b18
SHA3-384 hash: 4bb4a7161df84b222dfe1daaa7ca2f811480ae15724ab60704cb8c03d70679e0ebb8f3e23513b3f7b87a48d088098798
SHA1 hash: c7047cf9ed6e4f43281af522d2c9c79755be4e49
MD5 hash: 992749a4c864e4fa32d075c997902e5a
humanhash: beryllium-lactose-zulu-spring
File name:6ed0051747d0d5fbf4273b02e7267a257a82217c4b474117ea853014218b2b18
Download: download sample
File size:4'417'711 bytes
First seen:2020-06-03 09:19:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dbbc718f7f0ca351f7a0e645fde2dbea
ssdeep 98304:3+I3L/wlG4UZej0jvy5SbWf+YFCbJBAUZLs2K6:3HPvyQaf+HbJVDK6
Threatray 58 similar samples on MalwareBazaar
TLSH C016D103F2818472D81719700C77673A6A36FF116F258A93B794FE6D1D732E2973628A
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vmpbad
Status:
Malicious
First seen:
2020-06-04 04:29:39 UTC
AV detection:
43 of 48 (89.58%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious behavior: RenamesItself
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments