MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 032170e439e3cd6bc109ae3c7ff12ef8f29e6dd1f46d047da2d9041d892a63d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 032170e439e3cd6bc109ae3c7ff12ef8f29e6dd1f46d047da2d9041d892a63d1
SHA3-384 hash: b05217ffb72d3e631cd1039f72dd5e939f69f47d8c7502e316d1a27f44e9fe90580456d8e7d87c8795ddaedf427dd113
SHA1 hash: e8997b47d76a734beb13fc41ef31b00b0f677d2c
MD5 hash: 7d37f0d333659df823c1eb48cdeb6292
humanhash: skylark-alanine-december-kitten
File name:a90f600c6221f1799d9fe51387ae632d
Download: download sample
File size:1'036'289 bytes
First seen:2020-11-17 14:46:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 73bcd0d3e95d7d74c27e71b6714faf5a
ssdeep 24576:68OEkkHBpOlUb+LwdXJm/a/ZSC77Lv+f6T8E:68OEkkismwJJm/ghbD
Threatray 79 similar samples on MalwareBazaar
TLSH 4225C09D53A61843D033463AECDFCE2EA082757E66A7D2B1B1C070EFB462B85511BB35
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
DNS request
Sending a custom TCP request
Creating a file
Moving of the original file
Deleting of the original file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 14:46:57 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Legitimate hosting services abused for malware hosting/C2
Deletes itself
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
032170e439e3cd6bc109ae3c7ff12ef8f29e6dd1f46d047da2d9041d892a63d1
MD5 hash:
7d37f0d333659df823c1eb48cdeb6292
SHA1 hash:
e8997b47d76a734beb13fc41ef31b00b0f677d2c
SH256 hash:
60cba9e47b7cd6e532620b1e0b166cbd666330c2fa5a3360ed89b4e2fe29d68c
MD5 hash:
3cfd4bd1e50a99285a332ee6cee82d8d
SHA1 hash:
10eb5f39bd74ab15ef127015bfcb326e2481ddf5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments