MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ae809a33d01626e77dcfd591902815692405d2fa1f6ae7df13ca248507e4562. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4ae809a33d01626e77dcfd591902815692405d2fa1f6ae7df13ca248507e4562
SHA3-384 hash: 7e425dee3e9b1c6e03a378b52b33ccedac6c3cf771b5d0eea72aab8d1bc8c83bb6d33d198546f468ae1893ba6a14ce23
SHA1 hash: 69ffe8f7ca565b6c07462d3c7c0eef2dd4a87f01
MD5 hash: f17b2ef7612dea0104c57192ee6c427d
humanhash: east-seventeen-ceiling-cup
File name:payload.exe
Download: download sample
File size:94'720 bytes
First seen:2020-03-18 04:43:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f86dec4a80961955a89e7ed62046cc0e (94 x Dharma, 1 x Crysis)
ssdeep 1536:mBwl+KXpsqN5vlwWYyhY9S4AAa/Q3YnqWgYnL8OxmskO1um3ty3aTwHXmh:Qw+asqN5aW/hLFuYngYnL8sk+um303a3
Threatray 9 similar samples on MalwareBazaar
TLSH 6293AE28C831D035F8A350FFCBF696FD9D644B20130394D797C15E49AB9AAD5F932A22
Reporter fbgwls245
Tags:#Ransomware #CrySis/#Dharma .IPM

Intelligence


File Origin
# of uploads :
1
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA

Comments