MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 744d7fc9796a48f7d5b1173b91d1b018f13f91db7798a3d9cfd27fb22d678898. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Win.Worm.Fasong-5


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 744d7fc9796a48f7d5b1173b91d1b018f13f91db7798a3d9cfd27fb22d678898
SHA3-384 hash: a213d59de2e1e4ed6a87513c73ac15423dd2a0ee328324a4f69d43fea74ee71f0585c14bb9bb905bd41d4e9983a358ce
SHA1 hash: 0a6cb0dd5c7fd8f582999a83049fa01d8cb35ced
MD5 hash: 591b9c746ce0094e184b229012fdb1b9
humanhash: cat-nuts-bakerloo-mike
File name:mysong.exe
Download: download sample
Signature Win.Worm.Fasong-5
File size:205'415 bytes
First seen:2022-02-16 08:08:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9a40b556f04c6c6d3d61394c56be6bd5 (3 x Win.Worm.Fasong-5)
ssdeep 3072:M1abGWGT2TK1dbzlF9OVtSZjCw8geIr/QAuCgNVfpxICuQsKUIZnY:9bpGtfoVtScw2RCgrzItQB
Threatray 3 similar samples on MalwareBazaar
TLSH T1CA1412415B7ADCE2E5910EF157132728178CC1C4BAADC7209659EE7B3A3E630DDB3606
Reporter adm1n_usa32
Tags:exe fasong Win.Worm.Fasong-5

Intelligence


File Origin
# of uploads :
1
# of downloads :
213
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
mysong.exe
Verdict:
Suspicious activity
Analysis date:
2022-02-16 08:07:45 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Creating a file
Creating a service
Creating a file in the Windows directory
Creating a file in the Program Files subdirectories
Enabling the 'hidden' option for recently created files
Creating a process from a recently created file
Creating a process with a hidden window
Searching for the window
Searching for synchronization primitives
Sending a custom TCP request
Enabling autorun for a service
Enabling autorun with the shell\open\command registry branches
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
autorun bancos packed scar
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
88 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes security center settings (notifications, updates, antivirus, firewall)
Creates files in the recycle bin to hide itself
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sets file extension default program settings to executables
Sigma detected: Execution from Suspicious Folder
Behaviour
Behavior Graph:
Threat name:
Win32.Worm.Fasong
Status:
Malicious
First seen:
2022-02-09 15:27:32 UTC
File Type:
PE (Exe)
Extracted files:
24
AV detection:
42 of 43 (97.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence upx
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Drops file in Windows directory
Adds Run key to start application
Enumerates connected drives
Executes dropped EXE
UPX packed file
Modifies system executable filetype association
Unpacked files
SH256 hash:
afb12eaf97eec57bb319b8f26693fa6c8e7c567538f89de3259fd9dcee9aa89a
MD5 hash:
2c1c0afcd08d467a8d490b57b8a34d80
SHA1 hash:
57d6f5bc1b72787af0e07a81cfeb41807ad9be97
SH256 hash:
744d7fc9796a48f7d5b1173b91d1b018f13f91db7798a3d9cfd27fb22d678898
MD5 hash:
591b9c746ce0094e184b229012fdb1b9
SHA1 hash:
0a6cb0dd5c7fd8f582999a83049fa01d8cb35ced
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments