MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ccc44f84fb5a1c2a6b783e1f0be04231454731b4184f180e68be2c34a72d6a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0ccc44f84fb5a1c2a6b783e1f0be04231454731b4184f180e68be2c34a72d6a5
SHA3-384 hash: 182648057e1eb1a07cab9d03b9b764a70cfff6009446b76a79387a3825bece1c57b1f5b7ce83cd1dc409d51a878eb0ba
SHA1 hash: 779cde612cbdc4599b0f462c234ad3a836c4f6ff
MD5 hash: 38fc0ab9474a0c700cdff7cbf1f5339e
humanhash: uncle-bravo-nineteen-april
File name:SecuriteInfo.com.HEUR.Trojan.Win32.Agent.gen.27187.32349
Download: download sample
File size:18'370'560 bytes
First seen:2023-02-15 15:43:24 UTC
Last seen:2023-03-30 23:33:13 UTC
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 393216:VdhNfw/BYBh9/1I/JWw4SFgx641eN23urq1CSyp+kVuXo8Iu1:VdhhCBY1iBWwLSxb8NyurqF4uXzIs
Threatray 17 similar samples on MalwareBazaar
TLSH T12907DDD17741C123E94B58268F5BD3AC931DFDA1FA30B8473260F34E9A3A8D39AA4715
TrID 98.2% (.MSI) Microsoft Windows Installer (454500/1/170)
1.7% (.) Generic OLE2 / Multistream Compound (8000/1)
Reporter SecuriteInfoCom
Tags:msi

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
83%
Tags:
expand.exe fingerprint greyware keylogger packed shell32.dll
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-02-15 15:45:43 UTC
File Type:
Binary (Archive)
Extracted files:
37
AV detection:
5 of 26 (19.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Suspicious use of SetThreadContext
Enumerates connected drives
Checks computer location settings
Drops startup file
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Microsoft Software Installer (MSI) msi 0ccc44f84fb5a1c2a6b783e1f0be04231454731b4184f180e68be2c34a72d6a5

(this sample)

  
Delivery method
Distributed via web download

Comments