MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eaca8287ec8d461a944da43f061dd197225ff77979c8acc7017bb1ea8301f3b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.ExtenBro


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: eaca8287ec8d461a944da43f061dd197225ff77979c8acc7017bb1ea8301f3b7
SHA3-384 hash: e78010e8aabbf3d3252a73e6d794580855a8ac5b6509befdfe4882120b8fb4a0e57ee6088abffd402daafc0dacf9d4a3
SHA1 hash: 674d4d7f725fb4302429dd8b81fbdbe54e026b60
MD5 hash: c553403224a78ba6f79769439b7503c2
humanhash: blue-carbon-cold-uniform
File name:eaca8287ec8d461a944da43f061dd197225ff77979c8acc7017bb1ea8301f3b7
Download: download sample
Signature Adware.ExtenBro
File size:765'350 bytes
First seen:2020-06-03 09:47:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2fb819a19fe4dee5c03e8c6a79342f79 (56 x Adware.InstallCore, 8 x RedLineStealer, 7 x Adware.ExtenBro)
ssdeep 12288:+yIFHiQEW+quct8UGgdeWWN9rHR171QK3R0+Cw9cV7WF8REE0WmMVxaxk3ah1gV:+yIpKW+37UURjCK3RVVU7KE07MVxdq1k
Threatray 3 similar samples on MalwareBazaar
TLSH DEF41207DD9DA5F1F02BB9B80E50094092DBA5DA1D3849E570BF4C89DF6FA40B53A3B1
Reporter raashidbhatt
Tags:Adware.ExtenBro exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Disbuk
Status:
Malicious
First seen:
2020-06-03 11:06:27 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Checks installed software on the system
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Adware.ExtenBro

Executable exe eaca8287ec8d461a944da43f061dd197225ff77979c8acc7017bb1ea8301f3b7

(this sample)

  
Delivery method
Distributed via web download

Comments