MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9390db4bf8afcd19f46bb69bc599d92b7d5d92fff5d92912fcc602e16beae42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b9390db4bf8afcd19f46bb69bc599d92b7d5d92fff5d92912fcc602e16beae42
SHA3-384 hash: cad5398976fc09dd7f2ef42994731ffd8271e3a691b3ed9b7028975d45381e1c947c131b30b125412f451e5e64272e11
SHA1 hash: 0a6347f6a57533a7ee50074523cc7173b6ccc609
MD5 hash: 9304ebbc50f2db1066a8a621fac29d90
humanhash: carolina-triple-double-utah
File name:b9390db4bf8afcd19f46bb69bc599d92b7d5d92fff5d92912fcc602e16beae42
Download: download sample
File size:1'931'136 bytes
First seen:2020-06-03 09:44:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7be4c98eebb39d282cdffc1cea8fb470 (661 x AveMariaRAT, 29 x Riskware.Generic)
ssdeep 12288:Q99Vbpgx4OuE+aCpBPY0PkI686WNUfWO6yuXzT5SPlSG9dA7W2FeDSIGVH/KIDgc:k1gg4CppEI6GGfWDkMQDbGV6eH8tkl
TLSH EF958CE03A4614F7D613A932AC1FC72169A1FE2D0728AF4F57763D09A877280B46E357
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 17:13:02 UTC
AV detection:
46 of 48 (95.83%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
warzonerat
Score:
  10/10
Tags:
family:warzonerat evasion infostealer persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious behavior: GetForegroundWindowSpam
Drops file in Windows directory
Suspicious use of SetThreadContext
Adds Run key to start application
Loads dropped DLL
Executes dropped EXE
Modifies Installed Components in the registry
Warzone RAT Payload
Modifies WinLogon for persistence
Modifies visiblity of hidden/system files in Explorer
WarzoneRat, AveMaria
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments