MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2 |
|---|---|
| SHA3-384 hash: | ae24dddeaedf8f405916356ffad54008487736b8a4842ba3e42ecffd89189be94a6ddf6032ed3ec5f6dfc81a80ea8134 |
| SHA1 hash: | b42ad1b713cca94d44abc97b23a99d1ddc2b8866 |
| MD5 hash: | 7d13e9ce716ea55bd73ea87055b8fa4b |
| humanhash: | wisconsin-gee-twenty-delta |
| File name: | SecuriteInfo.com.Win32.Heur.31538.12460 |
| Download: | download sample |
| File size: | 5'016'576 bytes |
| First seen: | 2020-04-20 19:21:51 UTC |
| Last seen: | 2020-04-20 19:45:49 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 9f35e965f6effd939584bb73fc92ab6c (1 x RedLineStealer, 1 x RecordBreaker) |
| ssdeep | 98304:WZKhG387D9HGnWnaXLHebEr4EDj1cVKkoCvc6ubAYwhzt5SrApfUAkvsfxP:w7M7D9WWnaXLHeEr1VcVKkoMYwhJVfUa |
| Threatray | 28 similar samples on MalwareBazaar |
| TLSH | 7736237753A91149D4DECC3AD63BBED570F3037B5E81F8B8449AADC626224E1E602E43 |
| Reporter |
Intelligence
File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Gathering data
Threat name:
Win32.Trojan.Xaparo
Status:
Malicious
First seen:
2020-04-20 17:11:32 UTC
File Type:
PE (Exe)
AV detection:
27 of 31 (87.10%)
Threat level:
2/5
Verdict:
malicious
Similar samples:
+ 18 additional samples on MalwareBazaar
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2
(this sample)
Delivery method
Distributed via web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::LoadLibraryA |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.