MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07bfebe8d71ba6f9d0f0b05d40648777a4200a5811a1c6000f825c6d3e8246a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 07bfebe8d71ba6f9d0f0b05d40648777a4200a5811a1c6000f825c6d3e8246a4
SHA3-384 hash: 1ed40590e60f468f14504d321461eccb5644c4482174ea2304b88fcc3a166cbd3a37f4608c3120574830edda4358ed3f
SHA1 hash: 171380a56c583722071c1433f2c4fa5c329f8039
MD5 hash: 9df2edcf7e8555f396d0e8fdaed7a3a8
humanhash: cola-bluebird-nuts-twelve
File name:9df2edcf7e8555f396d0e8fdaed7a3a8.exe
Download: download sample
Signature RaccoonStealer
File size:596'992 bytes
First seen:2020-05-18 07:25:38 UTC
Last seen:2020-05-18 08:22:47 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 59c9951075648745f5e0ce8a58c08d3f (2 x RaccoonStealer)
ssdeep 12288:YV/56hcnkP9ZUrVOOln13KVRn9gPzg8hAJpfxQtGBWJQ9:YV/Eh9ZUrVDl16Xn9gPzVkS8B
Threatray 319 similar samples on MalwareBazaar
TLSH 70C41221F192C072C93682B58965C6E0633F7E105768458B379A3B2F3EF16D22F6B356
Reporter abuse_ch
Tags:exe RaccoonStealer


Avatar
abuse_ch
RaccoonStealer C2:
http://34.105.255.170/gate/log.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Gandcrab
Status:
Malicious
First seen:
2020-05-18 07:35:38 UTC
File Type:
PE (Exe)
Extracted files:
22
AV detection:
28 of 31 (90.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RaccoonStealer

Executable exe 07bfebe8d71ba6f9d0f0b05d40648777a4200a5811a1c6000f825c6d3e8246a4

(this sample)

  
Delivery method
Distributed via web download

Comments