MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0 |
|---|---|
| SHA3-384 hash: | 6ae89187693fbf04d822d3fe01040d8ace13566258b36af6df867a28ef1929939d897ac2dd1bd435f3de28f9cce989ae |
| SHA1 hash: | b7d23aca436d62c836868d04eeb1ebd3e5c8062e |
| MD5 hash: | 91f5932590c540b6bbe60d5a31443514 |
| humanhash: | early-pluto-mike-ack |
| File name: | SecuriteInfo.com.W32.Agentwdcr.AY.11831.7446 |
| Download: | download sample |
| File size: | 49'152 bytes |
| First seen: | 2022-07-07 19:50:59 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | a50e815adb2cfe3e58d388c791946db8 (3 x Babadeda, 2 x njrat, 2 x DCRat) |
| ssdeep | 768:tRgcf0JQ+4j9GWRO9KnCnQwm8ALJxCiE2vDGoh+XzscH+5i1GU20I8eDNRX2Rc8k:tff+Q39GcOqrjLJFE8D/aL6iMU2OeJpt |
| Threatray | 151 similar samples on MalwareBazaar |
| TLSH | T1EB2301A8A41E70FFFEE4E83952F1978CD3A81671209C1F714D08D4AA74B69C7B9D206C |
| TrID | 41.1% (.EXE) UPX compressed Win32 Executable (27066/9/6) 25.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 10.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| Reporter | |
| Tags: | exe |
Intelligence
File Origin
# of uploads :
1
# of downloads :
285
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a window
Using the Windows Management Instrumentation requests
Sending a UDP request
Forced system process termination
DNS request
Sending a custom TCP request
Result
Malware family:
n/a
Score:
6/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
overlay packed shell32.dll
Malware family:
Gorgon Group
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Machine Learning detection for sample
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Behaviour
Behavior Graph:
Detection(s):
Suspicious file
Verdict:
malicious
Similar samples:
+ 141 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
8/10
Tags:
upx
Behaviour
Suspicious use of WriteProcessMemory
UPX packed file
Unpacked files
SH256 hash:
3643e8a687e91189611ad8fbea8bbdaecfb19c9fcf2469b0bfd4250f98aaff1e
MD5 hash:
773a2560668744da68aa4ad3da8df899
SHA1 hash:
b4b86bb3c2ccf8852dfc52f5881121d7badf1491
SH256 hash:
35df2690237d5367bdc9d80d185bd685244096e62f2bdf45e7b2c07cc3dd57a0
MD5 hash:
91f5932590c540b6bbe60d5a31443514
SHA1 hash:
b7d23aca436d62c836868d04eeb1ebd3e5c8062e
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.23
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.