MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07154d473fb63a6dae072ddd35ddd525aec37cc415fd5acad68ce8b400a79b70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 07154d473fb63a6dae072ddd35ddd525aec37cc415fd5acad68ce8b400a79b70
SHA3-384 hash: 6640959f108d64f2ffa699f782765fb2a22baa92049d2236a07b4ceefe1ea4e453ff6b903c4f8d82202e69afff74d5c3
SHA1 hash: 26b54c34f811a60323b8a3dc9d6ee5b070948405
MD5 hash: 249ad87d168a2df0901fc13792a4a9f8
humanhash: single-failed-pasta-florida
File name:a54b5eba4f83db5985000b2f25dfb65e
Download: download sample
File size:1'036'289 bytes
First seen:2020-11-17 15:44:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 73bcd0d3e95d7d74c27e71b6714faf5a
ssdeep 24576:9PWB0GA8Hl7euNacgPiwG5B4afPb7hIMa/ZSC77Lv+f6T8E:tWBLFTg6LB4IhJghbD
Threatray 91 similar samples on MalwareBazaar
TLSH 6A25C01D179D4647C0DB6B37D89EEA3B017A2C3C6BB3D2A6B25A38CA3191BC55437324
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
DNS request
Sending a custom TCP request
Creating a file
Moving of the original file
Deleting of the original file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 15:54:24 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Unpacked files
SH256 hash:
07154d473fb63a6dae072ddd35ddd525aec37cc415fd5acad68ce8b400a79b70
MD5 hash:
249ad87d168a2df0901fc13792a4a9f8
SHA1 hash:
26b54c34f811a60323b8a3dc9d6ee5b070948405
SH256 hash:
3a651e954869dbddc8e35c8e2a873d9c628d58fd3646b795c535b5ad8d8bf1a0
MD5 hash:
db64c21ae117ac1ef5a75a9a71c4d27c
SHA1 hash:
5f8cc38a361631b92a97b2f754852e6254523eb1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments