MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 2
| SHA256 hash: | f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a |
|---|---|
| SHA3-384 hash: | 222602937e689a8911f5ab70c9a091f77f937841a512736a5007b9bb29ea027c9c513666a75f29cf1462f463ba82fdda |
| SHA1 hash: | 63c7588db91dd8ae10ebf68d0df50af2e2574075 |
| MD5 hash: | fbea358bc53fd5dd7b3960bc391711b0 |
| humanhash: | hamper-india-jig-oklahoma |
| File name: | SecuriteInfo.com.Generic.mg.fbea358bc53fd5dd.24337 |
| Download: | download sample |
| File size: | 238'592 bytes |
| First seen: | 2020-04-10 18:36:26 UTC |
| Last seen: | 2020-04-10 19:31:46 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 6144:t7LVw2g+FJWeNMcmiz9NL+BV4eGLPe+ZhiuqL05MDrYh:Re2XFJWe/miz9Z+BV4PjUnQ |
| Threatray | 71 similar samples on MalwareBazaar |
| TLSH | AD344B253AEF5019F073EFB55AE875C6DA6EBA333606E45D2092038A4723B40ED9153F |
| Reporter |
Intelligence
File Origin
# of uploads :
2
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-10 16:34:06 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
26 of 31 (83.87%)
Threat level:
5/5
Verdict:
unknown
Similar samples:
+ 61 additional samples on MalwareBazaar
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe f5c1cfaf3b4793e3a93ed8cef3efd02e809e2c701178b2f3dcd548e89d139e1a
(this sample)
Delivery method
Distributed via web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.