MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a1752d81c865b605efa5e0afbe440c2cf957029a2181bb9e02c0862bca0383b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Fabookie


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 2a1752d81c865b605efa5e0afbe440c2cf957029a2181bb9e02c0862bca0383b
SHA3-384 hash: a5a12f843cacf575008da90c40c315dab3a744fe0c914e36e64fec1f0d91648ff6ae195ecb237408f9ffbcb035478bf2
SHA1 hash: 2d43e4ba1acf792b88667948461f4db235013f17
MD5 hash: 94dd9d2404fc059abb54043932327c76
humanhash: black-july-bulldog-river
File name:file
Download: download sample
Signature Fabookie
File size:457'728 bytes
First seen:2023-03-01 21:42:00 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7bae02ef14998d8530ddf0278301170f (3 x Fabookie)
ssdeep 6144:C8aMyDtA083XIMxEZ/mRfhTp+e5t5kkUgRGerEhgVIXFML:C5GIuEZ/mce5ZaerLIX
Threatray 14 similar samples on MalwareBazaar
TLSH T1A6A41819FBB448E0C196C635CDBE827BE272BD830A15930B4255FF9E3FF351069A8681
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 04dcd4c282e0f000 (37 x Fabookie)
Reporter jstrosch
Tags:exe Fabookie X64

Intelligence


File Origin
# of uploads :
1
# of downloads :
219
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2206.exe
Verdict:
Malicious activity
Analysis date:
2023-03-01 20:45:31 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Sending an HTTP GET request
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive greyware obfuscated shell32.dll upatre
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Fabookie
Detection:
malicious
Classification:
troj.spyw
Score:
84 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Yara detected Fabookie
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Minerva
Status:
Malicious
First seen:
2023-03-01 21:31:31 UTC
File Type:
PE+ (Exe)
Extracted files:
110
AV detection:
14 of 25 (56.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
spyware stealer
Behaviour
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
2a1752d81c865b605efa5e0afbe440c2cf957029a2181bb9e02c0862bca0383b
MD5 hash:
94dd9d2404fc059abb54043932327c76
SHA1 hash:
2d43e4ba1acf792b88667948461f4db235013f17
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Fabookie

Executable exe 2a1752d81c865b605efa5e0afbe440c2cf957029a2181bb9e02c0862bca0383b

(this sample)

  
Delivery method
Distributed via web download

Comments