MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 362d5d092e84e514f534881c7c1686f625a4b6882739df90a329e190ef027991. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mekotio


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 362d5d092e84e514f534881c7c1686f625a4b6882739df90a329e190ef027991
SHA3-384 hash: ba6da3e2e280f6fb22a7fe27b70d55665ef83cb780870b9d2bca3bff22fb7684e1c4d53d542d89c0ab6128f7b138ba97
SHA1 hash: bcbf4f76116bbd1305c80e6741040473bfb31bb3
MD5 hash: 0f1580aedb4703754ceda2fa85dd98e5
humanhash: berlin-freddie-video-zebra
File name:ses09.ig
Download: download sample
Signature Mekotio
File size:7'688'789 bytes
First seen:2022-04-27 09:45:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:KWLygPWIlcOlezsILiWcBkyBgekHIL1NXyCgaK0XPq5sCE9ktlZH0YLVRmO1H13n:KWLTuIVMzpcGyt11NibaRiE9kXZVa0hD
TLSH T13A7633272C9B3527294DBD6D18C55394A704B8BBAA3719AA97CAC510F1E3FD32480DCF
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter dgsecnet
Tags:Mekotio zip


Avatar
dgsecnet
zip with AHK Interpreter + AHK scripp + Malicious dll

Intelligence


File Origin
# of uploads :
1
# of downloads :
307
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control.exe expand.exe greyware hh.exe keylogger
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Infostealer.Fragtor
Status:
Malicious
First seen:
2022-04-27 09:46:20 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
11 of 42 (26.19%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
evasion themida trojan
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mekotio

zip 362d5d092e84e514f534881c7c1686f625a4b6882739df90a329e190ef027991

(this sample)

Comments