MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 013ed964d37e80ee700dd98ba83bc25692ee92b4895b92eed17c4ef5359432f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 013ed964d37e80ee700dd98ba83bc25692ee92b4895b92eed17c4ef5359432f8
SHA3-384 hash: 026762b21b49e6678ae2b401e15f52a82543a000994f927f160d25e80c4c00163f00a936fea387173b4a710173e78215
SHA1 hash: 8a7de1581df4a927a1b5144af9d590750649aa2c
MD5 hash: 13694c1e016d5a35d902070111f63d18
humanhash: failed-cola-white-louisiana
File name:13694c1e016d5a35d902070111f63d18.exe
Download: download sample
Signature DanaBot
File size:978'432 bytes
First seen:2020-05-02 07:57:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 10080279f86c8f524876f5bf41c92c73 (1 x DanaBot)
ssdeep 24576:nnrmNg9r6EAsSDBpvEwL55pkRT8cDbhvKyew4:n39r6/DjlL55rcHE5w4
Threatray 37 similar samples on MalwareBazaar
TLSH 662523596BF72123F1B1A930313486B07BA7BE307A70A29D1654116C1F786E35AB0F6F
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
779
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe 013ed964d37e80ee700dd98ba83bc25692ee92b4895b92eed17c4ef5359432f8

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::SetSecurityDescriptorSacl
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegSetValueExW

Comments