MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 374dcc8821e47ae2c106930ec577c60081dd3f52ae16e2bc4d3b49b63e1c4b0b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 374dcc8821e47ae2c106930ec577c60081dd3f52ae16e2bc4d3b49b63e1c4b0b
SHA3-384 hash: 6ec3349b89d1b8a05ca73b76c20613d79229b88bf75372157d5d49085161d0aed7cbd63f6ce58cbdf4dc2acdba214082
SHA1 hash: 414b2961f23185f7d28c5780a26e8a50dd53f4b6
MD5 hash: 133a86efa95f1bfe254af8ce030cf40b
humanhash: india-cup-sweet-venus
File name:133a86efa95f1bfe254af8ce030cf40b
Download: download sample
File size:142'201 bytes
First seen:2021-09-04 12:34:26 UTC
Last seen:2021-09-04 14:13:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c4b8b0aba9f9c876ca624bdbda64d516 (1 x Koadic, 1 x Sality, 1 x CoinMiner)
ssdeep 1536:hmHmtXYg8pWDM021JlT68U/xoA4Yo0f2DRS+xTb7fy:gHmteWDM02nlcGTYo0f2DRS+pHy
Threatray 2 similar samples on MalwareBazaar
TLSH T1B1D31761AB84402BE48108352106DB3FD5BA7C31707A3423EB69BDF37D7B5D6842AD8E
dhash icon 1270cca8b8f0f010
Reporter zbetcheckin
Tags:32 exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
145
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Creating a window
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 477689 Sample: TM6itqz6tX Startdate: 04/09/2021 Architecture: WINDOWS Score: 56 14 Multi AV Scanner detection for submitted file 2->14 16 Machine Learning detection for sample 2->16 7 TM6itqz6tX.exe 5 2->7         started        process3 signatures4 18 Contains functionality to detect sleep reduction / modifications 7->18 10 cmd.exe 2 7->10         started        process5 process6 12 conhost.exe 10->12         started       
Threat name:
Win32.Trojan.Zusy
Status:
Malicious
First seen:
2021-09-01 12:44:33 UTC
AV detection:
11 of 42 (26.19%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Unpacked files
SH256 hash:
374dcc8821e47ae2c106930ec577c60081dd3f52ae16e2bc4d3b49b63e1c4b0b
MD5 hash:
133a86efa95f1bfe254af8ce030cf40b
SHA1 hash:
414b2961f23185f7d28c5780a26e8a50dd53f4b6
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 374dcc8821e47ae2c106930ec577c60081dd3f52ae16e2bc4d3b49b63e1c4b0b

(this sample)

  
Delivery method
Distributed via web download

Comments