MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2
SHA3-384 hash: ae24dddeaedf8f405916356ffad54008487736b8a4842ba3e42ecffd89189be94a6ddf6032ed3ec5f6dfc81a80ea8134
SHA1 hash: b42ad1b713cca94d44abc97b23a99d1ddc2b8866
MD5 hash: 7d13e9ce716ea55bd73ea87055b8fa4b
humanhash: wisconsin-gee-twenty-delta
File name:SecuriteInfo.com.Win32.Heur.31538.12460
Download: download sample
File size:5'016'576 bytes
First seen:2020-04-20 19:21:51 UTC
Last seen:2020-04-20 19:45:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 9f35e965f6effd939584bb73fc92ab6c (1 x RedLineStealer, 1 x RecordBreaker)
ssdeep 98304:WZKhG387D9HGnWnaXLHebEr4EDj1cVKkoCvc6ubAYwhzt5SrApfUAkvsfxP:w7M7D9WWnaXLHeEr1VcVKkoMYwhJVfUa
Threatray 28 similar samples on MalwareBazaar
TLSH 7736237753A91149D4DECC3AD63BBED570F3037B5E81F8B8449AADC626224E1E602E43
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 1e04c1e4eefe23f454553364e757209462f2561d8455628b296b1dbe83fc6ec2

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA

Comments