MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2eb16dbc1097a590f07787ab285a013f5fe235287cb4fb948d4f9cce9efa5dbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 2eb16dbc1097a590f07787ab285a013f5fe235287cb4fb948d4f9cce9efa5dbc
SHA3-384 hash: 70ffca80f50b79cdbac82dce4985a71231d02ff20a7b71a141d55dedfc570f60e4c61da1e6d2859fac232d3943356828
SHA1 hash: 596977d016edc850f3dfccc91296724c68bc22f2
MD5 hash: dd9625be4a1201c6dfb205c12cf3a381
humanhash: yankee-uniform-april-beryllium
File name:2eb16dbc1097a590f07787ab285a013f5fe235287cb4fb948d4f9cce9efa5dbc
Download: download sample
File size:448'793 bytes
First seen:2022-07-06 16:24:34 UTC
Last seen:2022-07-06 16:47:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 35b01f45366554734382fafeae109e68
ssdeep 6144:ztPXkQM9JS95/2sbgUFZr4AyFQyHAl2rIk35w8wF3XLnCScqTbTp2InXjNhAOKYq:zF5M98951jczCrA0k35wn3X7Nhkr
TLSH T1CA94AE02F582C032D4F61430626E9BB6987C2530232A19F7E7D54D7BAEB41E27739B97
TrID 40.3% (.EXE) Win64 Executable (generic) (10523/12/4)
19.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
17.2% (.EXE) Win32 Executable (generic) (4505/5/1)
7.7% (.EXE) OS/2 Executable (generic) (2029/13)
7.6% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter Anonymous
Tags:dll Vsingle

Intelligence


File Origin
# of uploads :
2
# of downloads :
210
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
graftor greyware nukesped overlay rat shell32.dll virus windows
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking mutex)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Casdet
Status:
Malicious
First seen:
2022-06-23 01:41:00 UTC
File Type:
PE (Dll)
AV detection:
27 of 41 (65.85%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
2eb16dbc1097a590f07787ab285a013f5fe235287cb4fb948d4f9cce9efa5dbc
MD5 hash:
dd9625be4a1201c6dfb205c12cf3a381
SHA1 hash:
596977d016edc850f3dfccc91296724c68bc22f2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_stackstrings
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments