MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 137e231adcacc0cf90db36a496b20a200b7bbe50e4a63b781778e185dfb47898. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 137e231adcacc0cf90db36a496b20a200b7bbe50e4a63b781778e185dfb47898
SHA3-384 hash: 53ea6f3b8c942d6663ea5ba4f7b24a6defe293d1a9ede5a40ad36602c6517d64edc0cd78da48e5a79ff9dde74fb68296
SHA1 hash: 8f4640f717bfc4878d9d375f8c666597b1c1f2d8
MD5 hash: e2c6bce10b20158f86863e0ade8d4863
humanhash: comet-sweet-november-magnesium
File name:a7bed02c8c29059a32b888b7ac45d4c8
Download: download sample
File size:105'472 bytes
First seen:2020-11-17 15:46:37 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash cd1141d5c773ab89f0404d96cc7847c5 (1 x CoinMiner)
ssdeep 1536:ThHBST3ezRi0nL+Bib/TTvcCoNSvBK5jzVxe2D9sJI+gs3Ql+lyvPDReMMJwj:TPzRi6+mvDmveQQxQ2+bReLJ
TLSH BEA3CF2238C1C132C4A2113548F4D7313EBAF57267A9528BBBA8E6BE1F307D4563675B
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Creating a file in the %temp% directory
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
DNS request
Connection attempt
Deleting of the original file
Enabling autorun by creating a file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 15:55:17 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Unpacked files
SH256 hash:
137e231adcacc0cf90db36a496b20a200b7bbe50e4a63b781778e185dfb47898
MD5 hash:
e2c6bce10b20158f86863e0ade8d4863
SHA1 hash:
8f4640f717bfc4878d9d375f8c666597b1c1f2d8
SH256 hash:
85e1440d651df28dd9ba120d9bde31e938d82145fde75fa10ad26dfcdc31b00f
MD5 hash:
902408a3a95656500eb57976096c2140
SHA1 hash:
ab8bfc6c2db12996d0f627344043c3a207bcb18d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments