MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a48467546d08abe1332b9b4684e07156b25681bf808744ab6500a4ff0d28c7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TA505


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4a48467546d08abe1332b9b4684e07156b25681bf808744ab6500a4ff0d28c7b
SHA3-384 hash: 9c0f2a10e1fc393429029b423c3129cd6fc57e3fcdab8404c295f8e36fa2f9f336cbd31e4d26d93a72b1a247f9deeeee
SHA1 hash: 44df19e96aa3abb3608a0a03ee5a685722956a9b
MD5 hash: 653d9da87cae15a787ddddf10735417e
humanhash: moon-blue-whiskey-lamp
File name:libIntel1.bin
Download: download sample
Signature TA505
File size:326'656 bytes
First seen:2020-06-25 13:51:04 UTC
Last seen:2020-06-25 14:52:34 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 51f2258e979f5fb6cc29d005190ba4da (1 x TA505)
ssdeep 6144:d8pc086DAaV2J/+ZQSWiO6Tr3ITsA4EliOJZdtYiEE+gzuHSi4sUdk7llUZSzYsT:/08s8JPYa4ElF7GilO0IUyYsX8Y
Threatray 50 similar samples on MalwareBazaar
TLSH 3D64F161AA529479C5DC003063BB5FBE75787EB43B40A9CB835C05E2EC252AAFD27713
Reporter JAMESWT_WT
Tags:32b dll TA505

Intelligence


File Origin
# of uploads :
2
# of downloads :
909
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Threat name:
Win32.Trojan.GraceWire
Status:
Malicious
First seen:
2020-06-25 13:11:29 UTC
File Type:
PE (Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
evasion spyware trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Modifies system certificate store
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments