MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3149e5bba6530fa8acbf36367fd05f0eb2ee98352c2ed59aef316c28f0663d76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3149e5bba6530fa8acbf36367fd05f0eb2ee98352c2ed59aef316c28f0663d76
SHA3-384 hash: e2ef03512b19d8299b32c74823c18f354c1b887af871528f4d3585005733fbc9cf5f0019ed64b75ce2846a8418505b90
SHA1 hash: 000caac77a724fe2fad711c7420c589d37ef7ca4
MD5 hash: 43a95ee1ddadeae9c4ef572605bfca5e
humanhash: lactose-victor-romeo-five
File name:rp0.tif.decode
Download: download sample
File size:55'296 bytes
First seen:2020-10-13 15:43:29 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash dae02f32a21e03ce65412f6e56942daa (123 x YellowCockatoo, 60 x CobaltStrike, 44 x JanelaRAT)
ssdeep 768:4lPD5R2Ox+yW18FopoltlQ8DR36PMtv1OZQVvI29eT9sW:2RnnyEYGL368v1oKW
Threatray 358 similar samples on MalwareBazaar
TLSH 13432C4A36897DDEC47A8932BB761ED0D758AD66430BD21F94C726ACD93D483BE003E1
Reporter srcr
Tags:exe


Avatar
srcr
Sample source: http://groups.us.to:69/rp0.tif (base64 decoded)

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.Tiggre
Status:
Malicious
First seen:
2019-01-31 13:32:29 UTC
File Type:
PE (.Net Dll)
Extracted files:
14
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
3149e5bba6530fa8acbf36367fd05f0eb2ee98352c2ed59aef316c28f0663d76
MD5 hash:
43a95ee1ddadeae9c4ef572605bfca5e
SHA1 hash:
000caac77a724fe2fad711c7420c589d37ef7ca4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments