MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30f166c009214739749ee34b1de5a09dbbb3d94b537a5b37316f31d01c1b60ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: 30f166c009214739749ee34b1de5a09dbbb3d94b537a5b37316f31d01c1b60ed
SHA3-384 hash: 97316b6663c11df0aeae19df59cc7bc63a7354314bebd673884a8fab42f0d8234bd13038a19f400eacac70bfcd6fac9f
SHA1 hash: e8d635d20214c58e302ae1b8064fd61439ee868d
MD5 hash: bd713350cfd475ad2bb8b5f566af1ac4
humanhash: delaware-may-three-double
File name:MarioKartEmuDownloader.zip
Download: download sample
File size:96'774 bytes
First seen:2024-08-30 21:28:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:hRnAV/U1H4iCe7LKbF5aQiV3jrtdZi8lenO0Nh/DbE/Dz8cBmhwDRYN4N:h9iUNT7LCb5artdI8cO0NJDg7hBmhSRP
TLSH T1F493123417C4B99B928FDD20B2BEA841C5D366C10650D52A7876F573311BBA7B02E9C9
Magika zip
Reporter Anonymous
Tags:zip


Avatar
Anonymous
Retrieved from https://itsthepartything.serv00.net/repo2/MarioKartEmuDownloader.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
461
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Mario Kart Rom Downloader.EXE
File size:203'264 bytes
SHA256 hash: e25ffd8251478187f053ab0d2dbb0fc7fdf4ba552ec7d07e6edbc5c74aa68ffd
MD5 hash: 7e0582cd96b1c383885e4f70fcdc3f79
MIME type:application/x-dosexec
File name:ReadmeMK.txt
File size:199 bytes
SHA256 hash: 3de63ddef6311823cc87e11110d02b69fa3919f369ef6d08c0f029ec79d8e5b5
MD5 hash: e0130bda49b2a45862ae0d4d391eae49
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
Banker Execution Network Static Dropper Dexter
Result
Verdict:
Suspicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
CAB epmicrosoft_visual_cc installer microsoft_visual_cc sfx
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.ForkBomb
Status:
Malicious
First seen:
2024-08-30 21:29:04 UTC
File Type:
Binary (Archive)
Extracted files:
26
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:win_redline_wextract_hunting_oct_2023
Author:Matthew @ Embee_Research
Description:Detects wextract archives related to redline/amadey

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 30f166c009214739749ee34b1de5a09dbbb3d94b537a5b37316f31d01c1b60ed

(this sample)

  
Delivery method
Distributed via web download

Comments