MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 22eedeec8258af5a76c94379b7984bb4e1d3a0aef8bfcb0554f34ed7148355ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Stop
Vendor detections: 14
| SHA256 hash: | 22eedeec8258af5a76c94379b7984bb4e1d3a0aef8bfcb0554f34ed7148355ac |
|---|---|
| SHA3-384 hash: | 715d854cf1d2159fb300df1753c4d055d5fc267633e9e269b68520e78521306261627ea846293e448537e357c8e3959c |
| SHA1 hash: | abd5ccebb3145e81deae46ec1278c80c7dc1b5de |
| MD5 hash: | 47355f25f69cb3c56a29e338a4780b92 |
| humanhash: | speaker-golf-quebec-friend |
| File name: | 47355f25f69cb3c56a29e338a4780b92.exe |
| Download: | download sample |
| Signature | Stop |
| File size: | 846'848 bytes |
| First seen: | 2022-08-07 09:45:37 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 08698d14d1e7fa83050959c8515b39ce (2 x Stop, 1 x ArkeiStealer, 1 x TeamBot) |
| ssdeep | 24576:8ZAXzP+4bNZhjcvn5lyuDOO9TVfak7/gTTbMu7:8a39cv5lDNxVrD |
| TLSH | T1E9050200BB90C435E4B222F45E7A936CB93E7E90972514CB62E53BDE67396E4EC31607 |
| TrID | 40.5% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 17.0% (.SCR) Windows screen saver (13101/52/3) 13.6% (.EXE) Win64 Executable (generic) (10523/12/4) 8.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.5% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| File icon (PE): | |
| dhash icon | b2dacabecee6baa6 (148 x RedLineStealer, 145 x Stop, 100 x Smoke Loader) |
| Reporter | |
| Tags: | exe Stop |
Indicators Of Compromise (IOCs)
Below is a list of indicators of compromise (IOCs) associated with this malware samples.
| IOC | ThreatFox Reference |
|---|---|
| http://159.69.102.194:1080/ | https://threatfox.abuse.ch/ioc/841762/ |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
d98d97f0fed4a9687c62c6554a1ed506e6a2d27fbf76078c0cb67850d05806f5
22eedeec8258af5a76c94379b7984bb4e1d3a0aef8bfcb0554f34ed7148355ac
20ec8ae5a8e4fe86e910d40b4db347a51b8cc84d4a851e8d000471e2933c20f3
61f9a4998fd5e3db092db5af0d8f1778c89fe3ec0d7c9f3723096303d8cad28d
19206ae96c605ebf5d0dcc13082c92244bc8de81655c83db61f7556b49063180
de79568aa1aafc72e526bb57ccf999ed9c3b76a24e180d34e22cc0b90c3aec1b
a8d2e2896594ddd274093ab56d71d5850872bb9a4527445ef6dd5a5525df0ae6
30c84e20e9d35c6f6fa892046af47913ac2e76bedb2662e1f1dfb73992ce4102
f7975bb947cffda4d31aa860546f2708c947f8963991e4ae83871d28f51559b1
c86e46822ef1e00c61577ee848a5bbcbc638824f8c638b7f753f59c1bdea36c9
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | BitcoinAddress |
|---|---|
| Author: | Didier Stevens (@DidierStevens) |
| Description: | Contains a valid Bitcoin address |
| Rule name: | MALWARE_Win_STOP |
|---|---|
| Author: | ditekSHen |
| Description: | Detects STOP ransomware |
| Rule name: | pdb_YARAify |
|---|---|
| Author: | @wowabiy314 |
| Description: | PDB |
| Rule name: | SUSP_XORed_URL_in_EXE |
|---|---|
| Author: | Florian Roth |
| Description: | Detects an XORed URL in an executable |
| Reference: | https://twitter.com/stvemillertime/status/1237035794973560834 |
| Rule name: | SUSP_XORed_URL_in_EXE_RID2E46 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects an XORed URL in an executable |
| Reference: | https://twitter.com/stvemillertime/status/1237035794973560834 |
| Rule name: | win_stop_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.stop. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.