MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10d30f99a7ff28b979466911f5ee0e451156e627682a1d639661dbb7c42c1b3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 10d30f99a7ff28b979466911f5ee0e451156e627682a1d639661dbb7c42c1b3f
SHA3-384 hash: 2971cec0b76f08469a1d4023eeb937b8d2f1c35d9f795e7f484911e2f7331eca6198879cc99d8b5f7c8163bc7d81279d
SHA1 hash: 6b76f46309dd288e93d765570d51136ecf7e7792
MD5 hash: 078fb584923487706390abc1a27a0459
humanhash: nineteen-blossom-robert-grey
File name:078fb584923487706390abc1a27a0459.exe
Download: download sample
File size:217'600 bytes
First seen:2023-03-08 20:55:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 90292de38e2bd6803e8e5e27da945a11 (2 x Fabookie)
ssdeep 3072:xVFE/ZYueQ6059PKEywh8QzEfae1NJLgf7nDVF6PUp1Yo3ICgC:MYue05FhyI8wEHN5gfzDVlVXg
Threatray 22 similar samples on MalwareBazaar
TLSH T14824C02172E859F9D67A4130DA235737CBB3BC541928172F12A0CB9A1F3351ABE1EB47
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon faf9f8d4d6ccc0c1 (6 x Fabookie, 4 x LummaStealer, 3 x AsyncRAT)
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
204
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Sending an HTTP GET request
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated packed shell32.dll
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-03-08 20:59:41 UTC
File Type:
PE+ (Exe)
Extracted files:
26
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
spyware stealer
Behaviour
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
10d30f99a7ff28b979466911f5ee0e451156e627682a1d639661dbb7c42c1b3f
MD5 hash:
078fb584923487706390abc1a27a0459
SHA1 hash:
6b76f46309dd288e93d765570d51136ecf7e7792
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 10d30f99a7ff28b979466911f5ee0e451156e627682a1d639661dbb7c42c1b3f

(this sample)

  
Delivery method
Distributed via web download

Comments