MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a3dfad85e59e53144c3c05413e16939d8c5bf194cd00ba4e2ca4feddbcca2cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 2a3dfad85e59e53144c3c05413e16939d8c5bf194cd00ba4e2ca4feddbcca2cb
SHA3-384 hash: 284cd096ea3a83fff05c940a9a8eeba074c805d567eef9d7b6a8e3a376c6ca0b5a57234575a9d9b71f465f7005f61bac
SHA1 hash: a34ae42b06ff30694ea514603ca19a34e3a3170c
MD5 hash: 9426fc850a62a8c668645ff60fb64ff7
humanhash: undress-pluto-mexico-white
File name:9426fc850a62a8c668645ff60fb64ff7.exe
Download: download sample
Signature DanaBot
File size:1'123'840 bytes
First seen:2021-08-16 12:16:52 UTC
Last seen:2021-08-16 12:53:35 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1a43dad8615b89dc6e5d071c17cc8026 (2 x RaccoonStealer, 1 x Smoke Loader, 1 x DanaBot)
ssdeep 24576:xnWzJ72qkIwwaJLbNwfiSdaijHShgY1VOYK:EzJ72ydaijy6oOY
Threatray 3'935 similar samples on MalwareBazaar
TLSH T14235236536D2D73AC42211F080B0E7F52DA57C70F21506972A3A7B2FEF76AD170A931A
dhash icon 1036787c76767e36 (1 x DanaBot)
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
306
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
9426fc850a62a8c668645ff60fb64ff7.exe
Verdict:
Malicious activity
Analysis date:
2021-08-16 12:17:19 UTC
Tags:
trojan danabot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Enabling the 'hidden' option for recently created files
Launching a process
Creating a process with a hidden window
Sending a UDP request
Creating a window
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Malicious Packer
Verdict:
Malicious
Result
Threat name:
DanaBot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Yara detected DanaBot stealer dll
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zenpak
Status:
Malicious
First seen:
2021-08-16 10:40:26 UTC
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Result
Malware family:
danabot
Score:
  10/10
Tags:
family:danabot banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Loads dropped DLL
Blocklisted process makes network request
Danabot
Danabot Loader Component
Unpacked files
SH256 hash:
65d5a44abe0c1b36c1cb6b5cca7cf3d0fde1e70e10aa0e78719602b7b1cc9c2a
MD5 hash:
e20a7327c72b4308abce23615a2be27f
SHA1 hash:
908a67e336e15d2a68b103e2a082e1146afd8e66
SH256 hash:
894626e137e0f0621675fdf5fc6278c0aa42db9b3a10ce21c7d4328469fa5ac8
MD5 hash:
e2376a71965f5c6a7690bf0826f29a71
SHA1 hash:
e9006ea1ad602e13f9f4fc664628c997b2804f22
SH256 hash:
2a3dfad85e59e53144c3c05413e16939d8c5bf194cd00ba4e2ca4feddbcca2cb
MD5 hash:
9426fc850a62a8c668645ff60fb64ff7
SHA1 hash:
a34ae42b06ff30694ea514603ca19a34e3a3170c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe 2a3dfad85e59e53144c3c05413e16939d8c5bf194cd00ba4e2ca4feddbcca2cb

(this sample)

Comments