MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a
SHA3-384 hash: 222602937e689a8911f5ab70c9a091f77f937841a512736a5007b9bb29ea027c9c513666a75f29cf1462f463ba82fdda
SHA1 hash: 63c7588db91dd8ae10ebf68d0df50af2e2574075
MD5 hash: fbea358bc53fd5dd7b3960bc391711b0
humanhash: hamper-india-jig-oklahoma
File name:SecuriteInfo.com.Generic.mg.fbea358bc53fd5dd.24337
Download: download sample
File size:238'592 bytes
First seen:2020-04-10 18:36:26 UTC
Last seen:2020-04-10 19:31:46 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 6144:t7LVw2g+FJWeNMcmiz9NL+BV4eGLPe+ZhiuqL05MDrYh:Re2XFJWe/miz9Z+BV4PjUnQ
Threatray 71 similar samples on MalwareBazaar
TLSH AD344B253AEF5019F073EFB55AE875C6DA6EBA333606E45D2092038A4723B40ED9153F
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
2
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-10 16:34:06 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments