MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ca84a00c6aa9f406f6eae854a8d33b5b264e0bbc0aed676acc29d066b5c2826. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Meterpreter


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2ca84a00c6aa9f406f6eae854a8d33b5b264e0bbc0aed676acc29d066b5c2826
SHA3-384 hash: 0b3545bf85da1d9c7904d742b8bb4c9cbf546d0bf7664e3e1401551f723fb592a83ada171866d65d534639a01b5339a7
SHA1 hash: ec67ef5feefc9b160094affbb5470d00ab471770
MD5 hash: e282559384e253ecf0874ed1fb1285a1
humanhash: louisiana-johnny-fifteen-social
File name:2.msi
Download: download sample
Signature Meterpreter
File size:159'744 bytes
First seen:2023-07-30 19:22:17 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 384:iHpe4ZvJXK7gzFM7WuQnsnoXgZs+5BCq26yy3M5BCqPN:Zmxa7gBMyulDCUyWMDC
TLSH T1CDF3A73736009331C14607368A6FD3E58F29AC5B8F6B1127359AB35D3F7299056B7AE0
TrID 88.4% (.MST) Windows SDK Setup Transform script (61000/1/5)
11.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Reporter ULTRAFRAUD
Tags:Meterpreter msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
alien meterpreter packed packed rozena shelma
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Metasploit
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to start reverse TCP shell (cmd.exe)
Drops executables to the windows directory (C:\Windows) and starts them
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Metasploit Payload
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1282802 Sample: 2.msi Startdate: 30/07/2023 Architecture: WINDOWS Score: 100 30 Found malware configuration 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 Antivirus detection for dropped file 2->34 36 3 other signatures 2->36 8 msiexec.exe 7 24 2->8         started        12 msiexec.exe 4 2->12         started        process3 file4 24 C:\Windows\Installer\MSI202.tmp, PE32+ 8->24 dropped 26 C:\Windows\Installer\5fff41.msi, Composite 8->26 dropped 38 Drops executables to the windows directory (C:\Windows) and starts them 8->38 14 MSI202.tmp 8->14         started        18 msiexec.exe 1 8->18         started        signatures5 process6 dnsIp7 28 3.110.135.114, 49679, 8080 AMAZON-02US United States 14->28 40 Antivirus detection for dropped file 14->40 42 Multi AV Scanner detection for dropped file 14->42 44 Contains functionality to start reverse TCP shell (cmd.exe) 14->44 20 cmd.exe 1 14->20         started        signatures8 process9 process10 22 conhost.exe 20->22         started       
Threat name:
Win64.Backdoor.Meterpreter
Status:
Malicious
First seen:
2023-07-27 06:17:15 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
23 of 38 (60.53%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Drops file in Windows directory
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Meterpreter

Microsoft Software Installer (MSI) msi 2ca84a00c6aa9f406f6eae854a8d33b5b264e0bbc0aed676acc29d066b5c2826

(this sample)

  
Delivery method
Distributed via web download

Comments