🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0
SHA3-384 hash: 6ae89187693fbf04d822d3fe01040d8ace13566258b36af6df867a28ef1929939d897ac2dd1bd435f3de28f9cce989ae
SHA1 hash: b7d23aca436d62c836868d04eeb1ebd3e5c8062e
MD5 hash: 91f5932590c540b6bbe60d5a31443514
humanhash: early-pluto-mike-ack
File name:SecuriteInfo.com.W32.Agentwdcr.AY.11831.7446
Download: download sample
File size:49'152 bytes
First seen:2022-07-07 19:50:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a50e815adb2cfe3e58d388c791946db8 (3 x Babadeda, 2 x njrat, 2 x DCRat)
ssdeep 768:tRgcf0JQ+4j9GWRO9KnCnQwm8ALJxCiE2vDGoh+XzscH+5i1GU20I8eDNRX2Rc8k:tff+Q39GcOqrjLJFE8D/aL6iMU2OeJpt
Threatray 151 similar samples on MalwareBazaar
TLSH T1EB2301A8A41E70FFFEE4E83952F1978CD3A81671209C1F714D08D4AA74B69C7B9D206C
TrID 41.1% (.EXE) UPX compressed Win32 Executable (27066/9/6)
25.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
10.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
285
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a window
Using the Windows Management Instrumentation requests
Sending a UDP request
Forced system process termination
DNS request
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed shell32.dll
Malware family:
Gorgon Group
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Machine Learning detection for sample
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Behaviour
Suspicious use of WriteProcessMemory
UPX packed file
Unpacked files
SH256 hash:
3643e8a687e91189611ad8fbea8bbdaecfb19c9fcf2469b0bfd4250f98aaff1e
MD5 hash:
773a2560668744da68aa4ad3da8df899
SHA1 hash:
b4b86bb3c2ccf8852dfc52f5881121d7badf1491
SH256 hash:
35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0
MD5 hash:
91f5932590c540b6bbe60d5a31443514
SHA1 hash:
b7d23aca436d62c836868d04eeb1ebd3e5c8062e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments