MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2101b0cbc46567edd0a5c6bdc673e5ac2dad20ca8b3b6bb00d88566dea9ee5ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 8 File information Comments

SHA256 hash: 2101b0cbc46567edd0a5c6bdc673e5ac2dad20ca8b3b6bb00d88566dea9ee5ed
SHA3-384 hash: e6783d809684892e4218748a808fa08a0b75249995b8d4d313a8c7f486ebbc9d734eae1c2943ea10d57b188c3316a6f8
SHA1 hash: 46fcd1408e8a4c7a3958fac025bb88edaf08801c
MD5 hash: 62c498915f7f3ec3b132d9d9498ce3d9
humanhash: kentucky-west-alabama-seven
File name:SecuriteInfo.com.TScope.Trojan.Delf.9212.14005
Download: download sample
File size:3'974'492 bytes
First seen:2024-01-04 04:18:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c8cc639128b993317f408dbb4b01f6e5
ssdeep 49152:ak+DAB4qEK1BC2e/GRzd+oyMfGBCsGyIToa/ng:aXgnzd+3CsK/ng
Threatray 1 similar samples on MalwareBazaar
TLSH T133068CA2B781C427C0B76F345D5B83F45429BB112E3C25CB77AA8E4C1F39A85797128B
TrID 51.7% (.EXE) Win32 Executable Borland Delphi 6 (262638/61)
21.1% (.EXE) Inno Setup installer (107240/4/30)
11.3% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
8.4% (.EXE) InstallShield setup (43053/19/16)
2.7% (.EXE) Win32 Executable Delphi generic (14182/79/4)
File icon (PE):PE icon
dhash icon d3c769258525555f (1 x Cybergate)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
324
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug anti-vm control hacktool hook keylogger lolbin overlay packed remote replace
Malware family:
Onlinegames
Verdict:
Suspicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
2101b0cbc46567edd0a5c6bdc673e5ac2dad20ca8b3b6bb00d88566dea9ee5ed
MD5 hash:
62c498915f7f3ec3b132d9d9498ce3d9
SHA1 hash:
46fcd1408e8a4c7a3958fac025bb88edaf08801c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:CGISscan_CGIScan
Author:yarGen Yara Rule Generator by Florian Roth
Description:Auto-generated rule on file CGIScan.exe
Rule name:Check_OutputDebugStringA_iat
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments