MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 005bff91c7c3ca88fc794d00d4882a634276c85b506679624b3b51a6a1aec6d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 005bff91c7c3ca88fc794d00d4882a634276c85b506679624b3b51a6a1aec6d1
SHA3-384 hash: b661d011307a7483367ed51c63d6b28beb69d0a9c79ab246e07148d36c63705e5e84963295857b0c83c542eec0dd76aa
SHA1 hash: a465c1ce1b740db7f6fd19b5eda18d2bfab107da
MD5 hash: 93b512b985f8b388a015738ccbf954ed
humanhash: kitten-texas-mike-november
File name:93b512b985f8b388a015738ccbf954ed.exe
Download: download sample
File size:4'325'609 bytes
First seen:2023-04-03 12:35:37 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 73ec795c6c369c6ce2c3b4c3f6477daa (12 x Gh0stRAT, 5 x MimiKatz, 1 x Redosdru)
ssdeep 98304:3i/XDlaVlI4AhZ67RlXoAfZROOxbK58+FrzpxsUGqbgtXOgc:3KD0m4A67DXfqOZ+8IIUGqbI+gc
Threatray 5 similar samples on MalwareBazaar
TLSH T1A21633688C60A617D0FD05B55FC725A34605A422AAF0DBBF29ECD35705381ECADF7E88
TrID 56.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
11.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
9.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.1% (.EXE) Win32 Executable (generic) (4505/5/1)
3.7% (.ICL) Windows Icons Library (generic) (2059/9)
File icon (PE):PE icon
dhash icon bcadaea686868633 (11 x Gh0stRAT)
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
195
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
93b512b985f8b388a015738ccbf954ed.exe
Verdict:
No threats detected
Analysis date:
2023-04-03 13:00:26 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file
Creating a window
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
83%
Tags:
overlay packed shell32.dll
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Backdoor.Farfli
Status:
Malicious
First seen:
2023-04-03 08:51:15 UTC
File Type:
PE (Exe)
Extracted files:
4
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
005bff91c7c3ca88fc794d00d4882a634276c85b506679624b3b51a6a1aec6d1
MD5 hash:
93b512b985f8b388a015738ccbf954ed
SHA1 hash:
a465c1ce1b740db7f6fd19b5eda18d2bfab107da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_get_eip
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 005bff91c7c3ca88fc794d00d4882a634276c85b506679624b3b51a6a1aec6d1

(this sample)

  
Delivery method
Distributed via web download

Comments