MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13af08593a4bd73dfcf9620842e8c86b24d6e30a2afe5b17aee21274eaf8a8b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 13af08593a4bd73dfcf9620842e8c86b24d6e30a2afe5b17aee21274eaf8a8b3
SHA3-384 hash: a34de6f55fa39305313961829b633d1cf118f0dc0031ce64e01314b29b1d1e0f16026b2e02a14d76d7deebd127322805
SHA1 hash: 941ffba6b44aa5a2f721da2589395476932fa194
MD5 hash: 1efc88f2318d3381cfbc335ed9a1a25f
humanhash: lamp-iowa-march-cat
File name:6ee6173a6ada3bf3c709ba18ea197827
Download: download sample
File size:19'550'918 bytes
First seen:2020-11-17 12:43:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat)
ssdeep 393216:W/D3EAPmG07FTAmph+HH5Zs2Dsa6skJHMLGPoefHZviYZ46v:W/LEMKhAmpM5Zs2DsDskUGPdBLPv
Threatray 52 similar samples on MalwareBazaar
TLSH 5B173354F5F024B0D6A6877A24259F598735BC207D7D8FDBA78A80BE0B20181CF773A6
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Deleting a recently created file
Threat name:
ByteCode-MSIL.Infostealer.Disco
Status:
Malicious
First seen:
2020-11-17 12:45:59 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
spyware
Behaviour
Suspicious use of WriteProcessMemory
JavaScript code in executable
Loads dropped DLL
Reads user/profile data of web browsers
Executes dropped EXE
Unpacked files
SH256 hash:
13af08593a4bd73dfcf9620842e8c86b24d6e30a2afe5b17aee21274eaf8a8b3
MD5 hash:
1efc88f2318d3381cfbc335ed9a1a25f
SHA1 hash:
941ffba6b44aa5a2f721da2589395476932fa194
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments