MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b54fb9596441cbdb7f2208b41a717adba83c5834a49c534f54d479131f750c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2b54fb9596441cbdb7f2208b41a717adba83c5834a49c534f54d479131f750c1
SHA3-384 hash: 83ebe3666a4dd1be6c7f9afe530c291c1aaf6713ffb73f13842a92e398111758185e2acb8fd523a2d2abd71c030bd05f
SHA1 hash: c306b6e2d76c0f9890a9258104583c11de289ba7
MD5 hash: 70f55d7830c7c9481af9754c87dc3f39
humanhash: illinois-potato-mississippi-echo
File name:70f55d7830c7c9481af9754c87dc3f39.exe
Download: download sample
Signature RaccoonStealer
File size:552'960 bytes
First seen:2020-05-15 11:09:10 UTC
Last seen:2020-05-15 12:25:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f7c7810020497ac02c4036464c4ff797 (1 x RaccoonStealer)
ssdeep 12288:nF9gor4d4r+Y2YYf+6HQNGL2ZU1i6+PVbyy:nfgoYY+Pl+xcLWU1UPVy
Threatray 321 similar samples on MalwareBazaar
TLSH CCC4E002F3E1B925E2668AF0DE2AB6E4563FBCE19D34662E1B64391F39F01D1C553312
Reporter abuse_ch
Tags:exe RaccoonStealer

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Racealer
Status:
Malicious
First seen:
2020-05-15 11:36:19 UTC
File Type:
PE (Exe)
Extracted files:
69
AV detection:
28 of 31 (90.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Modifies system certificate store
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RaccoonStealer

Executable exe 2b54fb9596441cbdb7f2208b41a717adba83c5834a49c534f54d479131f750c1

(this sample)

  
Delivery method
Distributed via web download

Comments