MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3242e0a736ef8ac90430a9f272ff30a81e2afc146fcb84a25c6e56e8192791e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3242e0a736ef8ac90430a9f272ff30a81e2afc146fcb84a25c6e56e8192791e4
SHA3-384 hash: 35892dac16fb838d7729a1485ccc05c5f7bb154f7405736609dd9c595a8da7dc4b5b184a45a11b244ab736c691055d3d
SHA1 hash: 9cd382eb91bfea5782dd09f589a31b47c2c2b53e
MD5 hash: 4685811c853ceaebc991c3a8406694bf
humanhash: pasta-lion-hot-sink
File name:SecuriteInfo.com.AutoIT_Compiled.11820.19429
Download: download sample
File size:905'728 bytes
First seen:2022-03-26 04:27:34 UTC
Last seen:2022-07-23 06:46:42 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 6c272312b690db5e72b315f1bb1db5b5
ssdeep 12288:oo6hrwBWQ1Ow8yPcT3ZinffOqJaFLGRTY7c223KmZaQRDSGEi:oo6dwBTj9U1wffO7FLG5Y7K3KmZ0GEi
Threatray 920 similar samples on MalwareBazaar
TLSH T16A157B42B3D7C0B2EFA119F2C57997362939BC35533888CB73D4382DD9A06C16A7535A
File icon (PE):PE icon
dhash icon fccccce4cccc4cbe (3 x DCRat, 2 x AsyncRAT, 1 x RedLineStealer)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
5
# of downloads :
237
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
AutoHotkey_1.1.33.10_setup.exe
Verdict:
Malicious activity
Analysis date:
2021-10-31 15:16:50 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
DNS request
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
CheckCmdLine
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe expand.exe greyware hh.exe keylogger
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
3242e0a736ef8ac90430a9f272ff30a81e2afc146fcb84a25c6e56e8192791e4
MD5 hash:
4685811c853ceaebc991c3a8406694bf
SHA1 hash:
9cd382eb91bfea5782dd09f589a31b47c2c2b53e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments