MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43aa01ebbd20c81ee60bd5b6bacabcdd0a84e0aeb892c0ea18383261dbcdb0fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 43aa01ebbd20c81ee60bd5b6bacabcdd0a84e0aeb892c0ea18383261dbcdb0fb
SHA3-384 hash: 923a67ed6aabdd8e4bb5c6896816cff32a88ac02ff75516e002ba4d73df16c0401a1656ba3ccba8ac42bc2316d706fa7
SHA1 hash: 8a4ef5c360400d1c3ec4775d2ed0023c0a9b9986
MD5 hash: b03a8ecc0967bf5eaa107130fdea6088
humanhash: fix-november-saturn-cup
File name:ac1b2b7f2c915a8f059d65133dc95f73
Download: download sample
File size:359'936 bytes
First seen:2020-11-17 15:11:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a5e1a2af8378e5bceb022f36c99ccc5a (12 x Formbook, 12 x AgentTesla)
ssdeep 6144:5FE9clGCkE8zkvC4bkSfRVtmUUZ8LoezTUOuW+BiyrhxP3YtGCiGzuy:+cfj8wIOZUZ8LokgWohhxPItBzf
TLSH D474E03534D2C533C422023A5DD496E5C93EB9255BE2688BFF440B6CAEB06F285B5E73
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Running batch commands
Unauthorized injection to a recently created process
Launching a process
Launching cmd.exe command interpreter
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-17 15:21:20 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments