MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0cf8ad6b4b1a25137fb42e0d831386e514620c851f782e37ebbd0d68105eb3d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Socks5Systemz
Vendor detections: 15
| SHA256 hash: | 0cf8ad6b4b1a25137fb42e0d831386e514620c851f782e37ebbd0d68105eb3d1 |
|---|---|
| SHA3-384 hash: | 60df80b6ba551444db42b3012ae704deaf76bd8b9ead2339fb7308837cc5611a3f423e75f1569e14f256ad7f7b0c3618 |
| SHA1 hash: | 88ab7379c0448a8505a78ca4265c465877350586 |
| MD5 hash: | 61991389203004219805a8de1da205a0 |
| humanhash: | golf-bulldog-maine-carbon |
| File name: | 61991389203004219805a8de1da205a0.exe |
| Download: | download sample |
| Signature | Socks5Systemz |
| File size: | 444'928 bytes |
| First seen: | 2024-10-15 21:45:53 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f8250be4329d3243c57b4a0ef0e0e955 (2 x Socks5Systemz) |
| ssdeep | 6144:CnKL2dxzZAuQvZ1Zx1dbtIXpnHbrZL0n3AikINDxL:CnKydxzqXvtxZgp7V0nwikMD |
| TLSH | T19794AF825691FCE0FA1246318D1ECEE876AEFC718E196B9733946F2F18711E2D263711 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10522/11/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 0203050122041200 (1 x Socks5Systemz) |
| Reporter | |
| Tags: | exe Socks5Systemz |
Indicators Of Compromise (IOCs)
Below is a list of indicators of compromise (IOCs) associated with this malware samples.
| IOC | ThreatFox Reference |
|---|---|
| http://91.211.248.13/316ea06a752c4625.php | https://threatfox.abuse.ch/ioc/1336784/ |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
75710e4a218440b1e9e330f231cfca45d5f7c41eacf9a7bd45bfd06042b79eac
71e552270361997f7b42b4ffa227ebd6a791948bfed757e61f2c3c7390bacaa3
0cf8ad6b4b1a25137fb42e0d831386e514620c851f782e37ebbd0d68105eb3d1
c4139579bd2c09fa3f876c15b04be33bd25e5c524fb687557771a07e99e22b9c
af1cd06ae9d17e6d05909d5031a72788989cb3980e7a456011091fc3ac77a07f
62469fe28764545471f447f88db812a162e9fe0af09f93b343c192a306600743
27ef27b61120a709590570f7fa86aa018f2e9b143bf97c4734720d2096b0bdf6
df6df345690b11a2fa15db713d36614a603af22e68d8b85bd7b663aaa48bf48e
2cfc6fe46f2025a7aeab3dbb5d271c49cb3341545313582ab6603351e75ee19c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CreateProcessW KERNEL32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::LoadLibraryA KERNEL32.dll::GetStartupInfoW KERNEL32.dll::GetStartupInfoA KERNEL32.dll::GetDiskFreeSpaceExA KERNEL32.dll::GetCommandLineW |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::WriteConsoleA KERNEL32.dll::WriteConsoleW KERNEL32.dll::ReadConsoleInputW KERNEL32.dll::SetStdHandle KERNEL32.dll::GetConsoleAliasExesW KERNEL32.dll::GetConsoleCP KERNEL32.dll::GetConsoleMode KERNEL32.dll::GetConsoleOutputCP |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CreateHardLinkW KERNEL32.dll::CreateFileA KERNEL32.dll::GetFileAttributesA KERNEL32.dll::GetTempPathA KERNEL32.dll::SetVolumeMountPointA |
| WIN_BASE_USER_API | Retrieves Account Information | KERNEL32.dll::GetComputerNameW |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.