🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 110fc287b499bea670dc2060d8a828727f350e9be446879ecfc7f71732ee15ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 110fc287b499bea670dc2060d8a828727f350e9be446879ecfc7f71732ee15ed
SHA3-384 hash: 52b2f436e3e933d6937425024000bff3c2963d1fc25401e304d6a72180414ea5ed982915f2e53e265c55209de978de55
SHA1 hash: 7b2f0e87f283d1ec4a756b380666a21e303579b0
MD5 hash: fe55aa33d7e0b4ef1cb72e61a0a7e581
humanhash: jupiter-single-indigo-social
File name:110fc287b499bea670dc2060d8a828727f350e9be446879ecfc7f71732ee15ed
Download: download sample
File size:4'122'112 bytes
First seen:2021-08-09 08:25:16 UTC
Last seen:2021-08-09 08:48:28 UTC
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 98304:l5nFFK+GEWJRgsnAWE05y4faRXsYA+tiQDnIjlBzpA7iQTWKKhgblOv:LFFKZEWJtni7XpA+MSIjl5pQnTWtrv
Threatray 10 similar samples on MalwareBazaar
TLSH T111163312F6819A7EC2FF0D71956FD621AA3DBE140B10C85AB368790F2C7149163F276B
Reporter JAMESWT_WT
Tags:D&K ENGINEERING DeK ENGINEERING msi signed

Code Signing Certificate

Organisation:D&K ENGINEERING
Issuer:Certum Extended Validation Code Signing CA SHA2
Algorithm:sha256WithRSAEncryption
Valid from:2021-05-26T13:22:50Z
Valid to:2022-05-26T13:22:50Z
Serial number: 6ce7a0c62f27fa98f78853e1ad11173f
Intelligence: 12 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 0cb6fba64ad12e52e753802016d11f19d46c53f5af49a03e9b04c6580d5831c1
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
103
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2021-07-30 13:31:21 UTC
File Type:
Binary (Archive)
Extracted files:
81
AV detection:
7 of 45 (15.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery exploit
Behaviour
Kills process with taskkill
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Drops file in Windows directory
Enumerates connected drives
Loads dropped DLL
Modifies file permissions
Blocklisted process makes network request
Executes dropped EXE
Possible privilege escalation attempt
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments