MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e72b9cc2d4e3dd77041c51c127bd366ee293f9cb0b94a986b2174c9888593f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



YellowCockatoo


Vendor detections: 1


Intelligence 1 IOCs YARA File information Comments

SHA256 hash: 0e72b9cc2d4e3dd77041c51c127bd366ee293f9cb0b94a986b2174c9888593f1
SHA3-384 hash: 23931319c3839400a3c7ca4503a5c8776a977f4af2300531578178e82e47a23fd112af4f9e1c2f440583e62fe5ee804d
SHA1 hash: af9ef28dbba5b0b6938af7541b6592732bae0d3a
MD5 hash: 757bd8b7321238aa31fac3e1fe658ee1
humanhash: magnesium-don-salami-neptune
File name:11543f09c416237d92090cebbefafdb2f03cec72a6f3fdedf8afe3c315181b5a.7z
Download: download sample
Signature YellowCockatoo
File size:4'305'234 bytes
First seen:2022-03-14 23:16:57 UTC
Last seen:2022-04-20 10:18:40 UTC
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 98304:aGJ7t/qMLUFQls80JKWEFobJua1PBJhzEnAfcCYQidt:BLYQiY5iJz15bziA7A
TLSH T19E1633E8D43A35FB9E6176935F164EC3141667860E1B83D8F20F23726F4AE4609A3D87
Reporter RussianPanda95
Tags:7z Jupyter Polazert solarmarker YellowCockatoo

Intelligence


File Origin
# of uploads :
7
# of downloads :
323
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
UNKNOWN
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Enumerates connected drives
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

YellowCockatoo

7z 0e72b9cc2d4e3dd77041c51c127bd366ee293f9cb0b94a986b2174c9888593f1

(this sample)

  
Delivery method
Distributed via web download

Comments