MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35352a7ac72a7962744268c134b1aacaba3eccd700e5c1378b4c13cf08d353ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 35352a7ac72a7962744268c134b1aacaba3eccd700e5c1378b4c13cf08d353ce
SHA3-384 hash: 5f7a370996995a54cbfda4484a092902a3236169a0a9afbf500de9a27d80e32edef826ffd8a3e3dfa8c7bd476822e5d9
SHA1 hash: 28ce674b5f9de2714d461b71f24f9ca472ae64e2
MD5 hash: 8b1b95033da018f8437575172247ee2e
humanhash: oranges-lion-mirror-high
File name:8b1b95033da018f8437575172247ee2e.exe
Download: download sample
File size:263'168 bytes
First seen:2023-12-14 07:16:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1d53e2bb204b1531bc66fb5a5f6443a4 (1 x Glupteba, 1 x CoinMiner, 1 x RecordBreaker)
ssdeep 3072:djxmgIq6rO8+T/hRVcIho5qNC5S3FhMMZIs:djx3Iq6rOhT/7VcIhUqZPMMZIs
TLSH T1B144C543A2913D84EA268B729E2FC6EC764DF650CE49B7762279AE1F04F1076C173750
TrID 38.6% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
29.0% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
9.7% (.EXE) Win64 Executable (generic) (10523/12/4)
6.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
File icon (PE):PE icon
dhash icon 000818080a030400
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
282
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
80%
Tags:
overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2023-12-14 07:17:06 UTC
File Type:
PE (Exe)
Extracted files:
61
AV detection:
17 of 23 (73.91%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
35352a7ac72a7962744268c134b1aacaba3eccd700e5c1378b4c13cf08d353ce
MD5 hash:
8b1b95033da018f8437575172247ee2e
SHA1 hash:
28ce674b5f9de2714d461b71f24f9ca472ae64e2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 35352a7ac72a7962744268c134b1aacaba3eccd700e5c1378b4c13cf08d353ce

(this sample)

  
Delivery method
Distributed via web download

Comments