MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 af6af9c2d50e7c692521dac219b7f2f23c6b677216267dcbaf44bd44f7290d70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: af6af9c2d50e7c692521dac219b7f2f23c6b677216267dcbaf44bd44f7290d70
SHA3-384 hash: 8c437899a42f75e452aca6ed993b23d61447b1b63d70162f3a82ca02ea036380476cfdedcee13564b0f2b026051da6ae
SHA1 hash: e5e16ba4f24fd939e6ece581704ac6ca9df4b0d6
MD5 hash: 05df30ff372ff1d27ab4874b50565c8f
humanhash: december-potato-shade-pluto
File name:KpAdXhHpGjNrCmg.dll
Download: download sample
File size:849'920 bytes
First seen:2020-03-24 15:35:43 UTC
Last seen:2020-03-24 17:55:38 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash b345fbea21400eca1030f3cca441e8d5
ssdeep 6144:RmFrmviQwtDkn6xEiMt3BDCmJzwpYPtz7EMUkLP2W5pwK9DgoU:BviT06jqBD9JzwU9HUzR
Threatray 56 similar samples on MalwareBazaar
TLSH 4B05F5ADA74348E3E7753A34E3C20E42552171D5E4200D8FBBBE2E5C6EA97A27C15EC4
Reporter Racco42
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsoleacc.dll::DllRegisterServer
MULTIMEDIA_APICan Play Multimediawinmm.dll::midiInGetErrorTextW
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA

Comments