MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48000c42895041ab94da59597b322a9afeacac40cbd8d7654115df6eaed44708. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 48000c42895041ab94da59597b322a9afeacac40cbd8d7654115df6eaed44708
SHA3-384 hash: ea4648cbbea23b06745e529181faf2f3de1a2a4837bf5180b40e911354f05cba526ad2dd84fbd5ea13f124a422b3f5b3
SHA1 hash: c61619f51bb3ded298be6ff4f37d657c7f4dee88
MD5 hash: d8d04a49a7ebe94d52daa21380c7f981
humanhash: double-quiet-carbon-spaghetti
File name:MHWv20200109-20201001FLiNG+67.exe
Download: download sample
File size:1'654'784 bytes
First seen:2020-10-12 10:41:16 UTC
Last seen:2020-10-12 11:48:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash a629facff1f65715d94567eb48725eef
ssdeep 24576:zQIQoxsvHM5QR7iv5Drj43MlCEs9jaPECkDtGQjnEdpDS5C:zQWEHfcvaWs9E/kwonQ
TLSH 8E75AE4A6B9446FCD0B7D13889539607F272780607718BDF13D886AB2F6B7E05E3A721
Reporter Jagdtiger88mm
Tags:GameHack malware

Intelligence


File Origin
# of uploads :
2
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Creating a file
DNS request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
Threat name:
Win64.PUA.GameHack
Status:
Malicious
First seen:
2020-10-02 23:14:48 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  1/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Unpacked files
SH256 hash:
48000c42895041ab94da59597b322a9afeacac40cbd8d7654115df6eaed44708
MD5 hash:
d8d04a49a7ebe94d52daa21380c7f981
SHA1 hash:
c61619f51bb3ded298be6ff4f37d657c7f4dee88
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments