MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0fecc31110c98a487e301d783c61d7f0e3e607854b5b94a01a96c73b07a99272. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0fecc31110c98a487e301d783c61d7f0e3e607854b5b94a01a96c73b07a99272
SHA3-384 hash: ff45cce1af414ea04c17552f9fad62965e5370cb962bfe081906582797bb40831bd5be0a77f1ca01f8321712218e2171
SHA1 hash: 90b5478bf87b14e1cfa72c76ae648df1d90c21e7
MD5 hash: c3da3f28afc1330b42a354fd22724dd3
humanhash: colorado-fruit-oklahoma-emma
File name:Injector.exe
Download: download sample
Signature CoinMiner
File size:252'416 bytes
First seen:2021-10-09 20:59:14 UTC
Last seen:2021-10-09 21:46:45 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 27516fd8750f40bdecf52a1420a0296a (12 x CoinMiner)
ssdeep 3072:ykw3v/tc7xk3xWNwCjPeUY9/QjoYpQtv4JNA:yj3Nc7xM9MPZY9/QscQSA
Threatray 91 similar samples on MalwareBazaar
TLSH T17334F4EA66808061DC5227B09FF2D616223D2CCCBEBCD90F39D6BD442F75DE518A160E
File icon (PE):PE icon
dhash icon 71c08ea6a68ec071 (1 x CoinMiner)
Reporter Anonymous
Tags:CoinMiner exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
239
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Injector.exe
Verdict:
No threats detected
Analysis date:
2021-10-09 21:00:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Running batch commands
Launching a process
Creating a process from a recently created file
Creating a process with a hidden window
Unauthorized injection to a system process
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Threat name:
Win64.Hacktool.Wovdnut
Status:
Malicious
First seen:
2021-10-09 21:00:08 UTC
AV detection:
17 of 45 (37.78%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments