MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 242713ef2f372f0d39ca8f01bd09c9f99bcfe850e156621c023dd9e0bfb9bd95. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Matrix


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 242713ef2f372f0d39ca8f01bd09c9f99bcfe850e156621c023dd9e0bfb9bd95
SHA3-384 hash: a0aece03900816e7b0b908b2cc81ffd0de3302daf8e59f03e5fa2b2768801b705f3420a97c7168de5df667cab53c1bf6
SHA1 hash: 31b50d84aa1af4f0e76a523382caba476f6e45dc
MD5 hash: a93bd199d34d21cc9102600c6ce782cf
humanhash: sierra-wolfram-charlie-cola
File name:iec56w4ibovnb4wc.onion_Library__Ransomeware__MatrixRansomware.bin.malw
Download: download sample
Signature Matrix
File size:1'253'888 bytes
First seen:2020-03-18 22:40:38 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ca3b1af31abe1beced65a635aa0c47a3 (4 x Matrix)
ssdeep 24576:NykKxXJdZiDTrfJR5ez1888K0aNE1eXTBoAlK/u95ByxXEfui:N8bcLK+KzlK/udyh/i
Threatray 76 similar samples on MalwareBazaar
TLSH FB457D27B24871BEE4294A364967C850793F7721BD128C166BF0492CEF395813F3AA5F
Reporter ov3rflow1
Tags:malw Matrix

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Matrix
Status:
Malicious
First seen:
2018-09-28 04:11:20 UTC
File Type:
PE (Exe)
Extracted files:
3
AV detection:
27 of 28 (96.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::AllocateAndInitializeSid
advapi32.dll::EqualSid
advapi32.dll::FreeSid
advapi32.dll::GetSidSubAuthorityCount
advapi32.dll::GetSidSubAuthority
NET_SHARE_APICan access Network Sharenetapi32.dll::NetShareEnum
SECURITY_BASE_APIUses Security Base APIadvapi32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CreateProcessW
advapi32.dll::OpenProcessToken
advapi32.dll::OpenThreadToken
kernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExW
kernel32.dll::LoadLibraryA
kernel32.dll::LoadLibraryW
kernel32.dll::GetDriveTypeW
kernel32.dll::GetVolumeInformationW
kernel32.dll::GetSystemInfo
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::GetConsoleOutputCP
kernel32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileW
kernel32.dll::DeleteFileW
kernel32.dll::MoveFileExW
kernel32.dll::GetFileAttributesW
kernel32.dll::FindFirstFileW
WIN_BASE_USER_APIRetrieves Account Informationkernel32.dll::GetComputerNameA
advapi32.dll::GetUserNameA
WIN_CRYPT_APIUses Windows Crypt APIadvapi32.dll::CryptAcquireContextW
advapi32.dll::CryptGenRandom
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExW
advapi32.dll::RegQueryValueExW
WIN_USER_APIPerforms GUI Actionsuser32.dll::PeekMessageW

Comments