MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4721929afd94b7a41b6e3a1085eb73f476c294699b772a72762f64601a06ae3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4721929afd94b7a41b6e3a1085eb73f476c294699b772a72762f64601a06ae3f
SHA3-384 hash: 8a13574b1b92d4851d0db106a546386849c23948f4813a7aef64c2f0af90c8c60c93934042d3662293e1a6ca8e402980
SHA1 hash: 6a8e1c467b6978c770585774bd02c7ed0fd43c67
MD5 hash: 7f38c0d3255bb7b171ef9346144c32a5
humanhash: berlin-queen-yellow-spaghetti
File name:a60f182b4eecdc80b3791b2404b7e856
Download: download sample
File size:1'036'289 bytes
First seen:2020-11-17 14:23:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fb1256fab57d2dfd02791ec2cff51231
ssdeep 24576:Czm1ayZ/fiyGKVnFJeRyTqgDiBkay3+idMxzNbSxla/ZSL77Lv+f6T8E:pZfxGYeATqxz7VNb+gwbD
Threatray 82 similar samples on MalwareBazaar
TLSH B725C00ED365A24BD4371236EE6ECA7A40A7287D7667DB2930B1B1E779207B0D116F30
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
DNS request
Sending a custom TCP request
Creating a file
Moving of the original file
Deleting of the original file
Result
Verdict:
0
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 14:24:25 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Legitimate hosting services abused for malware hosting/C2
Deletes itself
Loads dropped DLL
Executes dropped EXE
ServiceHost packer
Unpacked files
SH256 hash:
4721929afd94b7a41b6e3a1085eb73f476c294699b772a72762f64601a06ae3f
MD5 hash:
7f38c0d3255bb7b171ef9346144c32a5
SHA1 hash:
6a8e1c467b6978c770585774bd02c7ed0fd43c67
SH256 hash:
05b18df1127ec3e8ef6535448ec78d51be642f1bd77cfa42f3bcab6b864c7587
MD5 hash:
f80f7dce5cb4f99a75621d034545a485
SHA1 hash:
48005e0cde3cc5d3653aa58c18fe884f752e2698
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments