MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 167d491785e99c6aec1e23ef064eceb9e7ac81af33262d7e3d3e51cc8759ce70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Emotet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 167d491785e99c6aec1e23ef064eceb9e7ac81af33262d7e3d3e51cc8759ce70
SHA3-384 hash: 390157945c771671f320d74075724d9837fc5fa57bfc069a7a9aebff2c1a2979fd624c1229c65bfc88104e6c0aa46360
SHA1 hash: 0b9cd4924329bbdac4acb3e26711c8718cb4b442
MD5 hash: d4ddccfc5a0890adf081f492bc2a1ee3
humanhash: pip-alabama-cat-zebra
File name:Bank_Swift_Copy.bat.exe
Download: download sample
Signature Emotet
File size:1'564'672 bytes
First seen:2020-04-30 07:34:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d331ad91a022c5414232e19c616528ad (1 x Pony, 1 x Emotet)
ssdeep 24576:OT249ogv1wo+FYhuO6/xhWTzCCoaYn5k8r61CPQtqBorTlYWBhE+V3mO:k9Rao+FY0OQvg2RRkT1ltqFWM4m
Threatray 407 similar samples on MalwareBazaar
TLSH A275D032B3609C72D7FA06319261C713D2B7FD025933DA0749EA184DBE763E1A5663CA
Reporter jarumlus
Tags:Emotet

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments