MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b5b729d7d3c954efe6f4c43c2f70d130d7305b073b851bfb119c6c84a473599. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 1b5b729d7d3c954efe6f4c43c2f70d130d7305b073b851bfb119c6c84a473599
SHA3-384 hash: ba3d787ab31bc3db55958848a563d663cfabf624794bcdfe99527c28709d077ad0b5ffc0ce148650b169d32de2c5b030
SHA1 hash: a0e32f8cc3ca1bed6309c3c5ae4200baac7bb8a4
MD5 hash: cb454c163fb621bd4428587f315c432b
humanhash: double-quebec-video-april
File name:cb454c163fb621bd4428587f315c432b.dll
Download: download sample
File size:903'358 bytes
First seen:2021-04-12 18:47:43 UTC
Last seen:2021-04-12 19:48:00 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 12288:LAlF6Uoww/SY6TB0bbg3dW3JHrvVDPjjqXtBIV0Q5VFRObABXOPOAu4FDCIe:LAboz/I6budWhdq9EROsB+GAu+w
Threatray 1 similar samples on MalwareBazaar
TLSH A2157D36F1D3C437D5737A7C8E2B91A8E826BD511D2CA55A7AE40E088F392813D1D2DB
Reporter abuse_ch
Tags:dll

Intelligence


File Origin
# of uploads :
2
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
1b5b729d7d3c954efe6f4c43c2f70d130d7305b073b851bfb119c6c84a473599
MD5 hash:
cb454c163fb621bd4428587f315c432b
SHA1 hash:
a0e32f8cc3ca1bed6309c3c5ae4200baac7bb8a4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DLL dll 1b5b729d7d3c954efe6f4c43c2f70d130d7305b073b851bfb119c6c84a473599

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-04-14 16:01:57 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0001.025] Anti-Behavioral Analysis::Software Breakpoints
1) [C0026.002] Data Micro-objective::XOR::Encode Data