🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03cf91ec7462a61bf48a9ffde7e481ceb3bc61e8184749e734744d55d792ef06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 03cf91ec7462a61bf48a9ffde7e481ceb3bc61e8184749e734744d55d792ef06
SHA3-384 hash: 67ffa6477136569206d7b876ba0d777877561790a6330d9b1e09546142c3121f8c6498bba6f5fd7e08fc3207c2f5925d
SHA1 hash: 51a88646f9770e09b3505bd5cbadc587abb952ba
MD5 hash: d4d9d430a03375831027769a481689c7
humanhash: bravo-friend-lemon-white
File name:Project.zip
Download: download sample
File size:24'436 bytes
First seen:2024-09-17 08:58:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:mOwsSHiTJ1ParIcSXOt//FLvwCqSQ/iTaP1kfmsiar1DcScl2xXCspocqmCpocqm:m9sSCTGrIJXOt//FLYCqSQKTaifmszrm
TLSH T1ECB2192A843F92C9DFEAFAB4B186465EFEDE4D8D4274B1379538D04C6C051D32A05B8B
Magika zip
Reporter smica83
Tags:apt DPRK zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
HU HU
File Archive Information

This file archive contains 14 file(s), sorted by their relevance:

File name:SlackToCsv.csproj.AssemblyReference.cache
File size:4'061 bytes
SHA256 hash: fff4f5f9a1770af9803ab8560b14244d01fb136fd77be38548f3a3350a99e8c2
MD5 hash: 33bb6252f7a2c46cb65135bc8528bd7e
MIME type:application/octet-stream
File name:DesignTimeResolveAssemblyReferencesInput.cache
File size:5'528 bytes
SHA256 hash: 8f5cd8bcc193844a9295fd41fd08c785cdde9ccc1130371744cec746d8570895
MD5 hash: 9bd4be893357434ff51656ce800fba31
MIME type:application/octet-stream
File name:Csv.cs
File size:983 bytes
SHA256 hash: bdcb2457e10f3308ae735249ddad410e4c12ad1316f58b9cdb092d3b3b330f61
MD5 hash: bcc106b966fc87365236ed0eac2474d4
MIME type:text/x-c++
File name:App.config
File size:184 bytes
SHA256 hash: 8d65429e0b2a82c11d3edc4ea04ed200aedfea1d7ef8b984e88a8e97cff54770
MD5 hash: 28960c034283c54b6f70673f77fd07fa
MIME type:text/xml
File name:Channel.cs
File size:430 bytes
SHA256 hash: b8a1991aa9d0d8586e846dc1d8d7856af20a564f1fffd35ee7694ef5ce8274f6
MD5 hash: c11ca12382fcd010f5f200a50e1e2ee3
MIME type:text/x-c++
File name:Message.cs
File size:1'016 bytes
SHA256 hash: 125d2304d4491828ae5910830d0493fc3be820a06b86e556d720e96dd6d8e3d6
MD5 hash: 0bcec98d84a79e66e2a8250b000d969a
MIME type:text/x-c++
File name:ImportSlack.cs
File size:3'290 bytes
SHA256 hash: 1b3e288fd5d34fea056ad28aa7d564e451a61247937a4c6ca35c0054abfe8826
MD5 hash: a9c3928cfb77eebfd7a94a12450870e5
MIME type:text/x-c++
File name:Program.cs
File size:1'157 bytes
SHA256 hash: 42c8a4861e0283aa30d45e78df8653dfa1147ed1140812aee337391ffba395af
MD5 hash: 6699124067548b51e8c22580524093d4
MIME type:text/x-c++
File name:User.cs
File size:419 bytes
SHA256 hash: 1fa2c4e92bdc45889cff3ea82c108a15dd49e671f004028949b4d9a982574548
MD5 hash: 266040c11ee5d8c33a8a43384beb769e
MIME type:text/x-c++
File name:SlackToCsv.Test.csproj
File size:2'875 bytes
SHA256 hash: c00c809842a3c400130b1810271460f7f7d0d2914eba07d3f212f01de3062b70
MD5 hash: c307342dbcd77dcf1fc5945e43937a69
MIME type:text/xml
File name:packages.config
File size:141 bytes
SHA256 hash: ae858b01aa924169ddda7953420e9a83a53df8c1889339574b7e061234f2c875
MD5 hash: 96034dce93aca8446d2373db1ce30c3a
MIME type:text/xml
File name:AssemblyInfo.cs
File size:1'401 bytes
SHA256 hash: 9e56ad15b04df7ec8f09d8c0c7a15490a2eddf3847c4b08a4760db2e39791146
MD5 hash: 7968496b0653c164f4c56370ec3cb0b1
MIME type:text/plain
File name:SlackToCsv.csproj
File size:2'993 bytes
SHA256 hash: 3fe1bf052b1ef4992accf711f73723ceaa2eda46cc43de0243f8111d714d88d3
MD5 hash: 8d5fde976a546d8eeeab9312654e3402
MIME type:text/xml
File name:SlackToCsv.sln
File size:1'469 bytes
SHA256 hash: f83fc7651d8398c1543035b1a899c28aa9a0ff8388fdad83cb6aadb05ef29bc4
MD5 hash: d3232b84d8d71191cd19002f6b1861e4
MIME type:text/plain
Vendor Threat Intelligence
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_APT29_WINELOADER_Backdoor
Author:daniyyell
Description:Detects APT29's WINELOADER backdoor variant used in phishing campaigns, this rule also detect bad pdf,shtml,htm and vbs or maybe more depends
Reference:https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties
Rule name:NET
Author:malware-lu

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments