🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 237bc833db8c72cedf0a09bd642567aa31cc74dd6bcfe5b67871f375d617ec85. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ArkeiStealer


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 237bc833db8c72cedf0a09bd642567aa31cc74dd6bcfe5b67871f375d617ec85
SHA3-384 hash: 823c185b23c5625f765dbca95f88c0167b965a57df83239a4517aca0ae928875aac96aa8adfc269c38099dcccba8f5f3
SHA1 hash: 24a7a32d9d4944fc2e9bc89867ef682ffe4b6e5d
MD5 hash: 1b010600ba6e9288ba1de8456a1d9261
humanhash: fix-victor-oklahoma-coffee
File name:237bc833db8c72cedf0a09bd642567aa31cc74dd6bcfe5b67871f375d617ec85
Download: download sample
Signature ArkeiStealer
File size:5'227'784 bytes
First seen:2021-11-25 12:35:45 UTC
Last seen:2022-06-30 11:54:17 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5a594319a0d69dbc452e748bcf05892e (31 x Gh0stRAT, 21 x ParallaxRAT, 15 x NetSupport)
ssdeep 98304:8Sir2GLhfKDyTuwdbvLMv4JROOLYG0WU7TKhhd1gonPcMg:LGRKDyTjDMvwOavbQWL1/cZ
Threatray 85 similar samples on MalwareBazaar
TLSH T1F536123FF268A53EC46A173245B39350997BBE64A81A8C1B07FC380DCF765601E3B656
File icon (PE):PE icon
dhash icon 5050d270cccc82ae (113 x Adware.Generic, 85 x OffLoader, 48 x ValleyRAT)
Reporter 0xhido
Tags:ArkeiStealer BABADEDA-Crypter exe lockbit

Intelligence


File Origin
# of uploads :
2
# of downloads :
863
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
237bc833db8c72cedf0a09bd642567aa31cc74dd6bcfe5b67871f375d617ec85
Verdict:
Suspicious activity
Analysis date:
2021-11-25 13:26:16 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Searching for the window
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
.NET source code contains in memory code execution
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file has a writeable .text section
Potentially malicious time measurement code found
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 528545 Sample: OGzuPn8ahY Startdate: 25/11/2021 Architecture: WINDOWS Score: 80 41 Antivirus / Scanner detection for submitted sample 2->41 43 Multi AV Scanner detection for submitted file 2->43 45 Yara detected Vidar stealer 2->45 47 3 other signatures 2->47 9 OGzuPn8ahY.exe 2 2->9         started        process3 file4 35 C:\Users\user\AppData\...\OGzuPn8ahY.tmp, PE32 9->35 dropped 49 Obfuscated command line found 9->49 13 OGzuPn8ahY.tmp 3 13 9->13         started        signatures5 process6 file7 37 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 13->37 dropped 16 OGzuPn8ahY.exe 2 13->16         started        process8 file9 25 C:\Users\user\AppData\...\OGzuPn8ahY.tmp, PE32 16->25 dropped 39 Obfuscated command line found 16->39 20 OGzuPn8ahY.tmp 5 237 16->20         started        signatures10 process11 file12 27 C:\Users\user\...\evreporter.exe (copy), PE32 20->27 dropped 29 C:\Users\user\...\swresample-1.dll (copy), PE32 20->29 dropped 31 C:\Users\user\...\pthreadGC2.dll (copy), PE32 20->31 dropped 33 36 other files (none is malicious) 20->33 dropped 23 evreporter.exe 20->23         started        process13
Threat name:
Win32.Trojan.Convagent
Status:
Malicious
First seen:
2021-10-10 03:07:00 UTC
File Type:
PE (Exe)
AV detection:
17 of 27 (62.96%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
4d1fb84d2034c51f62e6e895e246d423f7b4fb2f1c2817a1aafc0a9c2cd68dc6
MD5 hash:
19d3e925bd3944acf03a70e2da39e46f
SHA1 hash:
b7710e87fecbd6abf2d1e60cfdf4f524f184850a
SH256 hash:
143e1c2939fa3f5e5b4f06bdda6d79b9fcdf7bee9d13175d23c5d37e70ff1661
MD5 hash:
1629a5cfe438a1773b1de46b55d2acae
SHA1 hash:
b9b62a639003810908b629eee8910215e61cae8b
SH256 hash:
b63926fcef0c292a21cfc808b49979d9cd53d07703184d7dffee66114eeb0c92
MD5 hash:
85866007804b691bbeda299116802247
SHA1 hash:
8188727403350ed977a8c1be597cf3c4bae8fdfb
SH256 hash:
237bc833db8c72cedf0a09bd642567aa31cc74dd6bcfe5b67871f375d617ec85
MD5 hash:
1b010600ba6e9288ba1de8456a1d9261
SHA1 hash:
24a7a32d9d4944fc2e9bc89867ef682ffe4b6e5d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments