MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe6778684fe56f143efd0bfae3e127f0c615f11d47e302e68a9eb1f83f7a6511. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fe6778684fe56f143efd0bfae3e127f0c615f11d47e302e68a9eb1f83f7a6511
SHA3-384 hash: 751135bebbc94f44acbcfc31ea96db0434725a6b65511ed84e475f6836a6a84616d78922caa8bbb0b5f9723604f5d13c
SHA1 hash: 2b1fe5a12b28bb953e5481f01945e629e741d64f
MD5 hash: 00a2dd02c0173b91704855771eab9096
humanhash: hamper-uniform-magazine-juliet
File name:mieqirl.dll
Download: download sample
File size:962'048 bytes
First seen:2020-03-20 20:01:06 UTC
Last seen:2020-03-20 21:48:43 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 9f389ccb31ebde8c1269363cb6c347de
ssdeep 6144:LT45Z024v0vOYxSGAvZcbhRf0WYpfR+PGc38kKuTd17cUotuPwo5USEWx6xVkYwo:Lbd82Y2veIfRSlstuPUX2
Threatray 38 similar samples on MalwareBazaar
TLSH 3F157A2EA64344DBE7752A34E3E30E03995171D6E8200D4F7E7E9E9C7B646A17C09EC2
Reporter Racco42
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DLL dll fe6778684fe56f143efd0bfae3e127f0c615f11d47e302e68a9eb1f83f7a6511

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsoleacc.dll::DllCanUnloadNow
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA

Comments