MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47b99e50430e9abad7326d1837ecdda5f995112b0b12406d23df5ef603d52a4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CrimsonRAT


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 47b99e50430e9abad7326d1837ecdda5f995112b0b12406d23df5ef603d52a4e
SHA3-384 hash: 76f7aa7ad2be7d13067a5c7227be808d1a0ba47916cd6b298ca54685840d34c34205337c355566bccf8732016a056516
SHA1 hash: e350b04dc8a3005649c8d54716b740c37d12dd53
MD5 hash: 8d42aaeaa6fc19c74b744ccf20e51150
humanhash: high-diet-illinois-undress
File name:nirtbivaes.bin
Download: download sample
Signature CrimsonRAT
File size:10'206'208 bytes
First seen:2020-11-13 14:12:26 UTC
Last seen:2024-07-24 13:48:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 768:slsbfwC9CcVl59JczGHZGpkANn8lO2NI7a5m2yR7xvB0fT/6Y2:0sDrVl5SJZelO2u7umxRSTi
Threatray 1 similar samples on MalwareBazaar
TLSH 3BA64AF6FE1A433DD8D4EBBD7B1091CCC619EFF15A05977E6600BA492A3B210467620E
Reporter JAMESWT_WT
Tags:CrimsonRAT

Intelligence


File Origin
# of uploads :
3
# of downloads :
1'472
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to capture screen (.Net source)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Potential time zone aware malware
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Ransomware.Foreign
Status:
Malicious
First seen:
2020-11-10 01:42:13 UTC
File Type:
PE (.Net Exe)
Extracted files:
14
AV detection:
21 of 28 (75.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
47b99e50430e9abad7326d1837ecdda5f995112b0b12406d23df5ef603d52a4e
MD5 hash:
8d42aaeaa6fc19c74b744ccf20e51150
SHA1 hash:
e350b04dc8a3005649c8d54716b740c37d12dd53
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments