MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35ae08dd66b6b142499ba173d3ff41f803e9c988a7ad8a25f62e31ed093144d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments 1

SHA256 hash: 35ae08dd66b6b142499ba173d3ff41f803e9c988a7ad8a25f62e31ed093144d9
SHA3-384 hash: f84b713e0eb8ffd88d415c8fe40383afd920c08977120dd6b224073aaf61c340cf8e0514bde88b800ec0f1b1a4ac0e1d
SHA1 hash: 623513c64b01c44619e23f6e42fa2d084c604bbc
MD5 hash: 8335cf7aad23e892220074908ed17e29
humanhash: july-muppet-autumn-october
File name:8335cf7aad23e892220074908ed17e29
Download: download sample
Signature DanaBot
File size:1'117'184 bytes
First seen:2022-03-18 18:18:56 UTC
Last seen:2022-03-18 20:00:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 75e06567c553fd5738bcb732c4034310 (3 x RedLineStealer, 1 x DanaBot, 1 x Stop)
ssdeep 24576:AqZOr/9LcNUrJ63EXxiFhb+cPeN8GamXEBTtc1xqdWeWnVk:BZOVcNUtSAAFhicPem7mX2WeWVk
TLSH T1FA3523243753D0FBC06982B4186BC107B5B7717256F5C94FB7842A2A5E207D2BAAA70F
File icon (PE):PE icon
dhash icon 5c595a3ce0c1c850 (5 x Stop, 5 x RedLineStealer, 3 x Smoke Loader)
Reporter zbetcheckin
Tags:32 DanaBot exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
658
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Creating a window
Launching a process
Sending a custom TCP request
Sending an HTTP GET request
Creating a file in the %temp% directory
Unauthorized injection to a system process
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
CheckCmdLine
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
84 / 100
Signature
Antivirus detection for URL or domain
Delayed program exit found
Machine Learning detection for sample
May use the Tor software to hide its network traffic
Multi AV Scanner detection for submitted file
Overwrites code with function prologues
Sigma detected: Suspicious Call by Ordinal
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.LockbitCrypt
Status:
Malicious
First seen:
2022-03-18 18:19:18 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
19 of 27 (70.37%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cloudeye
Result
Malware family:
n/a
Score:
  10/10
Tags:
suricata
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Suspicious use of SetThreadContext
Blocklisted process makes network request
suricata: ET MALWARE Danabot Key Exchange Request
Unpacked files
SH256 hash:
92774e0b9a9e078fef9f5639d701041d681387d5289f4ce85934c67737589e21
MD5 hash:
6fcbc23f67781711075a7076130357c5
SHA1 hash:
e671284444853708c2d695d1fc9e1ae4310499e5
SH256 hash:
35ae08dd66b6b142499ba173d3ff41f803e9c988a7ad8a25f62e31ed093144d9
MD5 hash:
8335cf7aad23e892220074908ed17e29
SHA1 hash:
623513c64b01c44619e23f6e42fa2d084c604bbc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe 35ae08dd66b6b142499ba173d3ff41f803e9c988a7ad8a25f62e31ed093144d9

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-03-18 18:18:58 UTC

url : hxxp://185.173.34.122/sopca16.exe