MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 348f79dc98ed91d11dea91d8295eac25cbd8a67daaa52ab0120708d2c7bde40c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 348f79dc98ed91d11dea91d8295eac25cbd8a67daaa52ab0120708d2c7bde40c
SHA3-384 hash: 76c3de9e2e0fb0c86cc8ffc90df243a3d49e0256b07ff9635a500eeaed84a297629fd080c59e752d04e3f4a56cff19e8
SHA1 hash: e7b8c6f31685df8767b676c32d1b5fb5d12a45cb
MD5 hash: ef636b7aa5741638a7d3be03270e5ca7
humanhash: comet-equal-high-high
File name:memorystream.exe
Download: download sample
File size:5'733'096 bytes
First seen:2022-02-26 12:12:25 UTC
Last seen:2022-02-26 13:55:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d1de500e42d2702177623521d4e86120
ssdeep 98304:ol+a3CT6UVG5bI2IdP2z7nTleK/bVSRxvqb03CiiQjtDW/HahZtS1eCW/89v9PBx:ZLG8GZqdA3QySXvqbWCAKs+oCWW9PBnx
Threatray 1 similar samples on MalwareBazaar
TLSH T107463323C5A348B9C7AABAF9425698F3FBB6FD698901C1379F90E6707707DA04E05740
Reporter 3xp0rtblog
Tags:exe Loader Summit

Intelligence


File Origin
# of uploads :
2
# of downloads :
324
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://bazaar.abuse.ch/download/348f79dc98ed91d11dea91d8295eac25cbd8a67daaa52ab0120708d2c7bde40c/
Verdict:
No threats detected
Analysis date:
2022-02-26 13:35:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Launching a process
Creating a window
Сreating synchronization primitives
Searching for the window
Unauthorized injection to a system process
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
GetTempPath
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug expand.exe overlay packed shell32.dll
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Cobalt Strike
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
68 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Creates a thread in another existing process (thread injection)
DLL side loading technique detected
Injects files into Windows application
Writes to foreign memory regions
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2022-02-26 12:13:16 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
9 of 28 (32.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
348f79dc98ed91d11dea91d8295eac25cbd8a67daaa52ab0120708d2c7bde40c
MD5 hash:
ef636b7aa5741638a7d3be03270e5ca7
SHA1 hash:
e7b8c6f31685df8767b676c32d1b5fb5d12a45cb
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments