MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ba65c6392cdc7f34eaf9c35f66d0e51fd7b384220a6f4f24a789b8560b4369e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2ba65c6392cdc7f34eaf9c35f66d0e51fd7b384220a6f4f24a789b8560b4369e
SHA3-384 hash: e8bab57b3fbe9f9990e092f6f66aa37caa3286f0e7559a53a77864ef96e57d9f84c44fe21160ca03cce52056cc44add3
SHA1 hash: 7230163d322898e77bb5fcf14b157a8980e10c24
MD5 hash: 7af02ab30180a5aa5933e4d51ab112a8
humanhash: tango-mirror-london-friend
File name:a0090450017d549ebca5cc6ff2ac16d9
Download: download sample
File size:385'026 bytes
First seen:2020-11-17 12:18:57 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b71ae52e8715ee7bfaa0c9df227db54a
ssdeep 6144:bX3bOU57Iz44gaDosJQO3zDo0W7cyqCxSngmMBqfycuPbUl0i5cD5J6U:V57IMh0Dj+0npM4dl0v5JF
Threatray 32 similar samples on MalwareBazaar
TLSH C284BD86735FAD19CC3E357714797201A8D2991FAE6C7D0EE568478A76A7C3FA08B00C
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Threat name:
Win32.Trojan.Khalesi
Status:
Malicious
First seen:
2020-11-17 12:24:06 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
2ba65c6392cdc7f34eaf9c35f66d0e51fd7b384220a6f4f24a789b8560b4369e
MD5 hash:
7af02ab30180a5aa5933e4d51ab112a8
SHA1 hash:
7230163d322898e77bb5fcf14b157a8980e10c24
SH256 hash:
2590e4c4f60325319db757f787a70f74ff6ddd2fac598c41df585b7aaf3be12e
MD5 hash:
f081c3fe38ed50921fac02d9fdb2974f
SHA1 hash:
23f6bc1de97a2afe576e2d4a02dc66797a02a304
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments