MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d4f89eb20efaf3a5a6dea14f885af9b447f83cfc5eb8c5027b67c95ddd62a23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Smoke Loader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2d4f89eb20efaf3a5a6dea14f885af9b447f83cfc5eb8c5027b67c95ddd62a23
SHA3-384 hash: 939f6e4ade09046a0bd166dce60ef5aa6351271192247564d45954fc7bce346ae7a436eade42a517f4b15a570771e691
SHA1 hash: 599682af55552d829d0056a4fcde642c0775ad91
MD5 hash: d1ccb9982487300fef2c56eebf0c9ca3
humanhash: harry-magnesium-maryland-lion
File name:d1ccb9982487300fef2c56eebf0c9ca3.exe
Download: download sample
Signature Smoke Loader
File size:211'094 bytes
First seen:2021-10-25 07:21:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b740a98397765fd7611816be8978d373 (2 x Smoke Loader, 2 x RedLineStealer, 1 x GCleaner)
ssdeep 6144:5ldfcC51keeZerR/m/Ej3/nDq1gze8yYieZ8g:ZfLvFleO3fDq1gnieZz
TLSH T19B248D00A7A0C435F0B316F845BA8379F93A7EA1AB7594CF62D01AEE56346E1EC70357
Reporter abuse_ch
Tags:Dofoil exe Smoke Loader

Intelligence


File Origin
# of uploads :
1
# of downloads :
195
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.StopCrypt
Status:
Malicious
First seen:
2021-10-25 07:22:07 UTC
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
2d4f89eb20efaf3a5a6dea14f885af9b447f83cfc5eb8c5027b67c95ddd62a23
MD5 hash:
d1ccb9982487300fef2c56eebf0c9ca3
SHA1 hash:
599682af55552d829d0056a4fcde642c0775ad91
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Smoke Loader

Executable exe 2d4f89eb20efaf3a5a6dea14f885af9b447f83cfc5eb8c5027b67c95ddd62a23

(this sample)

  
Delivery method
Distributed via web download

Comments