MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 455a7ebf67aec7b4d6cc18ed930bde491c0327ba5e24968514dd9b3449a7c374. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 455a7ebf67aec7b4d6cc18ed930bde491c0327ba5e24968514dd9b3449a7c374
SHA3-384 hash: dddbf5d0830741ca5a3a1af6493928361f51c338d162b597208029f9846eb4dde848105c5624c96fad67528a074ae5d9
SHA1 hash: 887781551bb75a53846ba0e1d359d2ec76304cb4
MD5 hash: bc969e0fa3c879e2acb3c360e5fe6940
humanhash: indigo-timing-venus-enemy
File name:455a7ebf67aec7b4d6cc18ed930bde491c0327ba5e24968514dd9b3449a7c374
Download: download sample
File size:3'233'792 bytes
First seen:2022-11-04 18:21:01 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:TtL+IOEM5ygqJTnPf1JkwKcBgsQIH0Zls8NGlLC50lbiP:xLemFlkwPgb0BCc
TLSH T14CE5DF166BA440E5D476C27D89B2E642F6B238950F31CBDF16A5535E3F33AE04D3A322
TrID 99.4% (.NULL) null bytes (2048000/1)
0.2% (.ISO) ISO 9660 CD image (5100/59/2)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter vxunderground
Tags:iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
US US
File Archive Information

This file archive contains 27 file(s), sorted by their relevance:

File name:231
File size:280 bytes
SHA256 hash: 928498f1591cff7d241b7869f785275bdfed2ca76f4543fa621b14eb91e6d7a2
MD5 hash: 910a2603508d5af00900d0ee40ef800a
MIME type:application/octet-stream
File name:134
File size:474 bytes
SHA256 hash: e554d8ea2fc01d39f3d6204c7197c772b2cb45855bf13e3a1d320405132eaff6
MD5 hash: 374a5506aee0dcefe60b67e02d4b21a3
MIME type:application/octet-stream
File name:121
File size:1'226 bytes
SHA256 hash: 4c37375f33f91f99241b97b7c74a11bc8152ae53e9d1b56ca346d6ded8ca62e0
MD5 hash: 8b4c230dcafaacbebd70af915362950b
MIME type:application/octet-stream
File name:127
File size:208 bytes
SHA256 hash: bda5e91c09b408008e3c8e70e7e3553b4a68736c39db25e8446c5dcc938e0841
MD5 hash: 4bcf41a6169190868662bdcd13fb43e0
MIME type:application/octet-stream
File name:string.txt
File size:6'910 bytes
SHA256 hash: c6af84f3d01f71ffa3fc99949d3e9b5b8db5ad89abc26e1230649f4af6cda8c7
MD5 hash: 723b4a363d7fdbecd9beabea7702f0ac
MIME type:application/octet-stream
File name:129
File size:1'464 bytes
SHA256 hash: ff15e637cb231d781a64887fbcc3bb71836bb364ef8ec06f44e26fb8f891c956
MD5 hash: afbbce04ca74a798a180a416418a0022
MIME type:application/octet-stream
File name:IBMTech-VNC.exe
File size:3'179'008 bytes
SHA256 hash: 37e30dc2faaabaf93f0539ffbde032461ab63a2c242fbe6e1f60a22344c8a334
MD5 hash: 5874d714fc2c5f32897be9380ff4e937
MIME type:application/x-dosexec
File name:122
File size:276 bytes
SHA256 hash: 9b5d6f84180645de54256d1190a25814d464e7d278cca6ca655b68565bf29a77
MD5 hash: 3a2c74cf3eb8af5b8e80cc2a097397e3
MIME type:application/octet-stream
File name:124
File size:888 bytes
SHA256 hash: 0f54e7bf6ead64a759ba82a199165749d2ea0937b16c29848687fc705ae003c1
MD5 hash: 7fcf8dd2f9aa5b89261201213a7cd0a9
MIME type:application/octet-stream
File name:123
File size:1'020 bytes
SHA256 hash: b2c1e1696953e16651af0ff6ac26f0c30bf7fc2b58eb7e4965edc7d5dfad96fe
MD5 hash: 6adb21b59963d60dc35b1a21639dc7e5
MIME type:application/octet-stream
File name:131
File size:360 bytes
SHA256 hash: 4a6a07cd48491712eb1b6cace03c3e981358fba4b339f2e7b16f0cb65410b8ab
MD5 hash: cc2486a29ad550d5bcb271cb8c58986a
MIME type:application/octet-stream
File name:136
File size:2'672 bytes
SHA256 hash: 453f66db1371fb3bf00a952e418dcdcee159d332e2616d66f2df17203dacf6b7
MD5 hash: ced650d111f813ab9d9501e8189fd4d2
MIME type:application/octet-stream
File name:3
File size:308 bytes
SHA256 hash: 727997ffe2fcff731850e3536e410d6eee0735fb20f15d78f66551da127764be
MD5 hash: 7fcfd155c03e666bf4b048a73bc9ca52
MIME type:application/octet-stream
File name:2
File size:308 bytes
SHA256 hash: cc1db626e63478ae495de90426e537c8873da8d9d2e0a118d8e3467eaa1d59b3
MD5 hash: c9ef291c8807319d9224005ea78c2b29
MIME type:application/octet-stream
File name:109
File size:20 bytes
SHA256 hash: c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
MD5 hash: a2baa01ccdea3190e4998a54dbc202a4
MIME type:application/vnd.lotus-1-2-3
File name:104
File size:34 bytes
SHA256 hash: 602cd95160cc398d3189ff328eddd35709fcc1b346666ed805c13061e895b215
MD5 hash: a665b984e221714430cdefd7b3b60256
MIME type:application/octet-stream
File name:141.bmp
File size:3'382 bytes
SHA256 hash: 79d62c39328d5414a8e557b0d308d87bf0a9d237d74c1e686497b9eb9ebcd7ed
MD5 hash: 642ccb56872a5bbca334af3af7ecf744
MIME type:image/bmp
File name:230
File size:392 bytes
SHA256 hash: 01afabdc7115b4f048537cd9f2d5efb0b4dbacb1b20b5b76a30ff871b6f9b6c1
MD5 hash: 320c18766b88e388765160a33478a666
MIME type:application/x-dbt
File name:108
File size:20 bytes
SHA256 hash: aa19a219f83823c2d583151fe8c575d3d2e47efa271cbefb23af7781167e22bc
MD5 hash: d102c84fa012b5daec71f067a5e69dbf
MIME type:application/octet-stream
File name:139.bmp
File size:9'360 bytes
SHA256 hash: 3ca815d0d09d12856aac0d88f3a84247f425b85843af83b5a9283cd4b1a68927
MD5 hash: 2b3759e71f83253df713989ca771677e
MIME type:image/bmp
File name:105
File size:20 bytes
SHA256 hash: ebd302bcd1b84ecbb03112dca0827fd62e584e470e2e37f0e350ea9e1ca68c9c
MD5 hash: 80b5fb843e4741ebe4a3330dcb8335ee
MIME type:application/octet-stream
File name:101.bmp
File size:2'166 bytes
SHA256 hash: dc0b8ac715bc900501fbbbdeb6673f7c02e66328eb298924423ef9adb33bb836
MD5 hash: b8efe121d22f00fb8b8c281b5331cdb1
MIME type:image/bmp
File name:106
File size:20 bytes
SHA256 hash: 45de95e2bc9da2d99016c89cba3816940f7ddb7f044c6d34b5f5c168c3b638ff
MD5 hash: 6a368971d47678239d334269be28300e
MIME type:application/octet-stream
File name:readme.txt
File size:73 bytes
SHA256 hash: 971029e46d950164a0709c8ffbd0dacf7f6a2a299558f69412975cd680662085
MD5 hash: 7334c7e813d287b4db559a748397eb8e
MIME type:text/plain
File name:137
File size:56 bytes
SHA256 hash: 14317cc6d843b62b8e78ca800cfeb2742ecfb2aef79db882dbb74ae7b8fcdf36
MD5 hash: b7f711ded73f936fa608f79f0858835d
MIME type:application/octet-stream
File name:102
File size:20 bytes
SHA256 hash: b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
MD5 hash: aff0f5e372bd49ceb9f615b9a04c97df
MIME type:application/vnd.lotus-1-2-3
File name:103
File size:20 bytes
SHA256 hash: 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
MD5 hash: 48e064acaba0088aa097b52394887587
MIME type:application/vnd.lotus-1-2-3
Vendor Threat Intelligence
Threat name:
Win64.Trojan.ZetaNile
Status:
Malicious
First seen:
2022-09-14 16:55:41 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
16 of 42 (38.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:meth_stackstrings
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments