MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9fd40d22f5ff232a91ed5a5cf02d0b2c1ef24ec36035c9dbf5af9b709db9b7bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 9fd40d22f5ff232a91ed5a5cf02d0b2c1ef24ec36035c9dbf5af9b709db9b7bc
SHA3-384 hash: 46a8dc8de9a9c653360f7458f801e0a22f42f65da332e1b4dbdbfc33ce41f58c3ff721048afc6059c9d4c8553ef62a67
SHA1 hash: 4d188361242cdaa825656cf8b13c4cfd03b5f7f8
MD5 hash: c4c1cdb0bbf2f9f14cf9da93393e6f52
humanhash: island-magnesium-chicken-north
File name:9fd40d22f5ff232a91ed5a5cf02d0b2c1ef24ec36035c9dbf5af9b709db9b7bc
Download: download sample
File size:4'417'711 bytes
First seen:2020-06-03 09:18:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dbbc718f7f0ca351f7a0e645fde2dbea
ssdeep 98304:3+I3L/wlG4UZej0jvy5SbWf+YFCbJBAUZLs2KF:3HPvyQaf+HbJVDKF
Threatray 58 similar samples on MalwareBazaar
TLSH BF16D103F2818472D81719700C77673A6A36FF116F258A93B794FE6D1D732E2973628A
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vmpbad
Status:
Malicious
First seen:
2020-06-03 17:35:49 UTC
AV detection:
44 of 48 (91.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious behavior: RenamesItself
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments