MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 479f664c5738beb4f29c1bf6c7346d5f36efa7b528c3f3fa4791455542bdca2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 479f664c5738beb4f29c1bf6c7346d5f36efa7b528c3f3fa4791455542bdca2e
SHA3-384 hash: dbb80f472936ad46da8a070960239b37db5654e3fe985c0fa16decc8ae11c0143d0647f13ffdcb3e19207278e8af41e9
SHA1 hash: 46db702ac78000beef28cd66a566458ffe9638c4
MD5 hash: 0050ae986380a240171e7a315d5e9b6c
humanhash: nebraska-fanta-cold-texas
File name:Adjunto mora mes abril 04 55Q2015 PDF 591614443490721954665390684759929290657106498586964723781278191212507219.exe
Download: download sample
File size:1'205'248 bytes
First seen:2020-04-14 23:15:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 179f7dbb794e8dc6e9e79b08307f1985
ssdeep 24576:UJSUnjtkIo3CRP9L5AA7gbO1rPjG3GHBHp+g5/od9ErT7A:GSUnOY9L5rRPIGHBHpVobYc
Threatray 11 similar samples on MalwareBazaar
TLSH 2845AE91A3C2C0FEFA8114BAD1E757725D35DE22831296C3F688FD715F211E0297E29A
Reporter Jirehlov
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
ole32.dll::CreateStreamOnHGlobal
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdipAlloc
MULTIMEDIA_APICan Play MultimediaAVIFIL32.dll::AVIStreamStart
AVICAP32.dll::capGetDriverDescriptionA
RAS_APIUses Remote AccessRASDLG.dll::RasPhonebookDlgA
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteA
URL_MONIKERS_APICan Download & Execute componentsurlmon.dll::IsAsyncMoniker
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetDriveTypeA
KERNEL32.dll::GetDriveTypeW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileMappingA
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::DeleteFileA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExW
ADVAPI32.dll::RegDeleteKeyW
ADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryInfoKeyW
ADVAPI32.dll::RegSetValueExW
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuW
USER32.dll::EmptyClipboard
USER32.dll::OpenClipboard
USER32.dll::PeekMessageW
USER32.dll::CreateWindowExW

Comments