🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 01b8b7240a20bd3eefe8b6ce48616fbccaffe26828f0cdc6b065b372f2c10a64. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LegionLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 01b8b7240a20bd3eefe8b6ce48616fbccaffe26828f0cdc6b065b372f2c10a64
SHA3-384 hash: f41c364a4f1939f3bfb28ade5caa70ca9482c165dba615a833129d0b6d25bc30e234cd1a68587fe79513caae7eee6f65
SHA1 hash: a7596347e2e3ffc91ff249b8aef91f1afc81cb00
MD5 hash: 1151e31e4976c6313efe6782e17f0c59
humanhash: march-maryland-juliet-floor
File name:Phshop_26.2.rar-121238.iso
Download: download sample
Signature LegionLoader
File size:64'335'872 bytes
First seen:2024-12-26 12:13:07 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 786432:gjkYXGZojVmrjV7eIAtehOTZ0oZ4sdUuzt/NCaY2ksCo:grXGcVmrjV7eIvhOTZ5RjVCa1tP
TLSH T13AE77C01B3FA4148F2F71EB17EBA45A594BABD521B30C0EF1244A60E1B71BC25BB5763
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter aachum
Tags:iso LegionLoader RobotDropper successroadway-com


Avatar
iamaachum
https://api.premiumexperiencegood.com/?353770=AM1GbWfqZQUAH4ECAEVTFwAMAAAAAABP.Phshop_26.2.rar.iso&flow_id=99&pkey=72e01ec8f10da660aaad&t=0.5&b=14.300670623779297&bt=new => https://api.premiumexperiencegood.com/s/dl/AM1GbWfqZQUAH4ECAEVTFwAMAAAAAABP/Phshop_26.2.rar-121238.iso

LegionLoader/RobotDropper C2: https://successroadway.com/updater.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
ES ES
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:hash.bin
File size:3'626'612 bytes
SHA256 hash: 20fcc97603920ac3cd45f2c6a5e1e4ccd1ff06f379b9a28f47657b45923ab826
MD5 hash: bf287abeb19bb1afa6103313a03c1745
MIME type:application/octet-stream
Signature LegionLoader
File name:setup.msi
File size:60'336'524 bytes
SHA256 hash: 404e2b3ecd486cf7a533790edbe22ab145c767f8c413a95570b0cc41c3b46143
MD5 hash: 99c84a1c2cf1acd2ddeb621561789acb
MIME type:application/x-msi
Signature LegionLoader
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm anti-vm cmd context-iso expand fingerprint fingerprint lolbin packed packed remote
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Drops file in System32 directory
Blocklisted process makes network request
Enumerates connected drives
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LegionLoader

iso 01b8b7240a20bd3eefe8b6ce48616fbccaffe26828f0cdc6b065b372f2c10a64

(this sample)

  
Delivery method
Distributed via web download

Comments