MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fe5f7997c9111800c88d2383cd3b62cb0c72eeb2bec3c5d72b5c1ac62d9145c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2fe5f7997c9111800c88d2383cd3b62cb0c72eeb2bec3c5d72b5c1ac62d9145c
SHA3-384 hash: 4d5682fb5fdbd46c316655510dc32ed0ceb672f3b7c3c57b03ef549440e09531bdfc9803ece86bb6a9966577421c7c3f
SHA1 hash: d3ffc507653fb8abccae0bf7e662eefb92d214f4
MD5 hash: 2703fba86d1d1ccd8888b9ef2798b5f9
humanhash: table-bulldog-berlin-happy
File name:CDE_8406727184.chm
Download: download sample
File size:15'086 bytes
First seen:2023-08-09 11:27:52 UTC
Last seen:Never
File type:
MIME type:application/octet-stream
ssdeep 192:uFx+rU4V0vV/eQzUxUOeizkj9A10I8viXqB1Z4491K1etNQL:uFxqNV5kOtQc0I0TiJotNa
TLSH T145628EB03F65411AC0A6E77A9FCD6E41BC193D4580D1704AF5EA0F0B05EBD589B70D87
TrID 81.0% (.CHI) Windows HELP Index (17144/6)
18.9% (.CHM) Windows HELP File (4000/1)
Reporter smica83
Tags:chm HUN

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade
Result
Verdict:
MALICIOUS
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2023-08-09 08:58:24 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Blocklisted process makes network request
Malware Config
Dropper Extraction:
https://sandiisells.com/cloud2.txt
Malware family:
AgentTesla.v4
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments