MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ebfad8fb0b23c73422d76527d9191dba2bdba248303ad05e884404fd133f7ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1ebfad8fb0b23c73422d76527d9191dba2bdba248303ad05e884404fd133f7ae
SHA3-384 hash: 6bc10cc8e06ac351cc2b7fed3da8dbf36e80d1e4bd8bd17045ad97e785fd3174224c5d2e84a4967b30da7e955a545d4a
SHA1 hash: 0c303981916ee99df7066d0f1d368f8328b1ed0d
MD5 hash: 7c86deae05186b895720675f87aa9338
humanhash: solar-victor-oven-table
File name:a95252e184ec5b6eff1edc5d7da3f44a
Download: download sample
File size:1'036'289 bytes
First seen:2020-11-17 15:30:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 73bcd0d3e95d7d74c27e71b6714faf5a
ssdeep 24576:zNsSKcC2tz3QlB6JQRsF4ZVpY8T+iji1ti/xTa/ZSC77Lv+f6T8E:AG3GMJQDXTB8Y/tghbD
Threatray 91 similar samples on MalwareBazaar
TLSH 7925CF2E73F2185FC23A4676E96FC75BA142DAB81AA7C3F171847AC770607C25182727
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
DNS request
Sending a custom TCP request
Creating a file
Moving of the original file
Deleting of the original file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 15:37:12 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Unpacked files
SH256 hash:
1ebfad8fb0b23c73422d76527d9191dba2bdba248303ad05e884404fd133f7ae
MD5 hash:
7c86deae05186b895720675f87aa9338
SHA1 hash:
0c303981916ee99df7066d0f1d368f8328b1ed0d
SH256 hash:
2d468916260a54bb745b09762def308fb9e7b36dbada7ae5728871caf8816f83
MD5 hash:
38dae7dd6bbda78d0c1cf0e1591fd399
SHA1 hash:
4c2163a98f83b7b01510222ab7d22fcd1f8ca085
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments