MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45aa8efb6b1a9a0e0091040bb99a7c37d346aaf306fa4e31e9d5d9f0fef56676. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 45aa8efb6b1a9a0e0091040bb99a7c37d346aaf306fa4e31e9d5d9f0fef56676
SHA3-384 hash: 313deb27c0a496aae4dead4e600d7cfd5ad2273f3dc1e4a5804f98055192d7a62929ea4f74fc61eff79e904a6f9ca68e
SHA1 hash: f53016812cd8f0c2de87f983fbdd2388de82db91
MD5 hash: 6cc78f2df0f8c52842ff1ad296907464
humanhash: magazine-winner-freddie-autumn
File name:mountdisk.dll
Download: download sample
File size:11'793'408 bytes
First seen:2022-05-09 18:55:19 UTC
Last seen:2022-05-09 19:32:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 59e16a2afa5b682bb9692bac873fa10c
ssdeep 196608:HqXa7c9ZfzvagPMbyoSYb34Q80LB2A17SQXlDQcF7d:37cZfzDEbyHYL2A17SQX6
Threatray 6 similar samples on MalwareBazaar
TLSH T102C6E055B21D61C2DA78C0387493DB322C3472EAA7396FC723E199A55C91BEB7BEC140
TrID 30.3% (.EXE) Win64 Executable (generic) (10523/12/4)
18.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
14.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
12.9% (.EXE) Win32 Executable (generic) (4505/5/1)
5.8% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Anonymous
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
279
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
7e17a043baa351cc507b4f47228a77d44773e3a2c5809bf4bdb0a0675d9eb9f0
Verdict:
Malicious activity
Analysis date:
2021-11-01 17:43:08 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug donut greyware packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains VNC / remote desktop functionality (version string found)
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 622969 Sample: mountdisk.dll Startdate: 09/05/2022 Architecture: WINDOWS Score: 68 22 kaceloj.com 2->22 26 Antivirus / Scanner detection for submitted sample 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Contains VNC / remote desktop functionality (version string found) 2->30 8 loaddll64.exe 1 2->8         started        signatures3 process4 process5 10 rundll32.exe 8->10         started        14 rundll32.exe 8->14         started        16 cmd.exe 1 8->16         started        18 6 other processes 8->18 dnsIp6 32 System process connects to network (likely due to code injection or exploit) 10->32 24 kaceloj.com 45.147.230.122, 443, 49766, 49767 COMBAHTONcombahtonGmbHDE Germany 14->24 20 rundll32.exe 16->20         started        signatures7 process8
Threat name:
Win64.Trojan.Vilers
Status:
Malicious
First seen:
2021-11-07 04:11:06 UTC
File Type:
PE+ (Dll)
AV detection:
19 of 41 (46.34%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Blocklisted process makes network request
Unpacked files
SH256 hash:
45aa8efb6b1a9a0e0091040bb99a7c37d346aaf306fa4e31e9d5d9f0fef56676
MD5 hash:
6cc78f2df0f8c52842ff1ad296907464
SHA1 hash:
f53016812cd8f0c2de87f983fbdd2388de82db91
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments