🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35b2319773272bbf3bef80ae283bcf71dfd28d3810a3b39a7d6a92d3e40ad3d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LegionLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 35b2319773272bbf3bef80ae283bcf71dfd28d3810a3b39a7d6a92d3e40ad3d7
SHA3-384 hash: 0e2ef0583b9778924f469d64459c79e9377e755c64df015b5cc48adbe84c7259a46f0bdd1ebfb0249ad74f7dcd2dac89
SHA1 hash: ae96700c9100352a96dc0f7f4878dda8e7aa1cfc
MD5 hash: 5a5affd5ae2f9961d4b8b1a88a2787b7
humanhash: triple-grey-carpet-romeo
File name:build.msi
Download: download sample
Signature LegionLoader
File size:69'404'160 bytes
First seen:2025-04-13 15:25:38 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 1572864:HyVmrjV7eInWOTZtgOcuZlbp/y3Vjw/6Z0fnZ:R2BgbY3Vr0P
TLSH T17CE78D01B3FA4148F2F75E717EBA55A594BABD521B30C0EF1204A60E1B72BC25BB1763
TrID 80.0% (.MSI) Microsoft Windows Installer (454500/1/170)
10.7% (.MST) Windows SDK Setup Transform script (61000/1/5)
7.8% (.MSP) Windows Installer Patch (44509/10/5)
1.4% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter aachum
Tags:LegionLoader msi redbluezone-com


Avatar
iamaachum
https://appnatural.monster/ => https://mega.nz/file/h3RRAJ5B#OzaPM1TCCXoPBYENqzQAzyTc2LPAln-HBGg2DQkW72Y

LegionLoader C2: https://redbluezone.com/diagnostics.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm cmd expand expired-cert fingerprint keylogger keylogger lolbin packed packed remote wix
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus detection for URL or domain
Suricata IDS alerts for network traffic
Behaviour
Behavior Graph:
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery persistence privilege_escalation
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Windows directory
Loads dropped DLL
Blocklisted process makes network request
Enumerates connected drives
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LegionLoader

Microsoft Software Installer (MSI) msi 35b2319773272bbf3bef80ae283bcf71dfd28d3810a3b39a7d6a92d3e40ad3d7

(this sample)

  
Delivery method
Distributed via web download

Comments