🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ba2c20a826f51ed753f4f4dd78118d6f371a2fd5b4b0a2ff640c8f046d4fb55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Expiro


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 2ba2c20a826f51ed753f4f4dd78118d6f371a2fd5b4b0a2ff640c8f046d4fb55
SHA3-384 hash: 1294a022f08c866ceb0908729b9092274b1c0dd238ab12683bbe7cbbb8758bc1606246bc82898779605dfd6c5d31414c
SHA1 hash: fd1a1709b4346a4ca307d01cb85b5d6beb633733
MD5 hash: 5a4135a79283d211cf21820a67e01a4f
humanhash: bacon-spaghetti-uranus-potato
File name:1.exe
Download: download sample
Signature Expiro
File size:2'863'616 bytes
First seen:2020-06-06 14:35:43 UTC
Last seen:2020-06-06 15:56:26 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f0070935b15a909b9dc00be7997e6112 (8 x GravityRAT, 5 x Glupteba, 1 x CobaltStrike)
ssdeep 24576:4Wrd9DgUhnyLCydJNj/uD2johpZYy13ZFb2v9xuxSJdqXy8YzK9tlQQ:4Wrd9DLyLvdJTohpth2v9x/dMqzKNQQ
Threatray 81 similar samples on MalwareBazaar
TLSH ACD55C03F8E619FACAFDE13185729721B671706903323B971F94467A192BBE4AF2D314
Reporter vm001cn
Tags:Expiro golang Ransomware

Intelligence


File Origin
# of uploads :
2
# of downloads :
207
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win64.Ransomware.Sorena
Status:
Malicious
First seen:
2020-06-05 18:49:54 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Result
Malware family:
vashsorena
Score:
  10/10
Tags:
family:vashsorena ransomware spyware
Behaviour
Kills process with taskkill
Suspicious use of WriteProcessMemory
Enumerates system info in registry
Modifies Control Panel
Modifies registry class
Runs net.exe
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Views/modifies file attributes
Drops file in Program Files directory
JavaScript code in executable
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
QVM360 commented on 2020-06-06 14:42:50 UTC

hunt: Jirehlov