MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4c9b6b07954c73955048fffc9845213a3cc2082f42baad16a6ed90251e8dbc1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4c9b6b07954c73955048fffc9845213a3cc2082f42baad16a6ed90251e8dbc1d
SHA3-384 hash: 07104955a1575865fd05ad84daafdf3249d8fa4f47985d014881540c525a40aa595bec667d00914f84d5aadba822dbc8
SHA1 hash: 3f6d0c228affddfc00bcb35d6864c757753466f3
MD5 hash: 58240dc8c834fda4434837b8fa7437a8
humanhash: mars-texas-nevada-social
File name:a767c3a77a57a1c39fbaa152f30986db
Download: download sample
File size:157'662 bytes
First seen:2020-11-17 15:49:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d7b2934b89bc50c5c343ad84032de88e (1 x Sytro)
ssdeep 3072:t3gbYiGULALwoOZ6CVLWX5XPK7XCz39yfgUvIDx5ZfeoEKzfiZHo:tYYiGULALwFypy7XCz9yIUAwKzfEo
Threatray 18 similar samples on MalwareBazaar
TLSH F0F3121ECB96D9D7FB93C4B3274BBD541B499D3C2A0C13B345E5BE3229641A1B263C82
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the Windows subdirectories
Creating a file in the Windows directory
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Worm.Soltern
Status:
Malicious
First seen:
2020-11-17 15:56:34 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Unpacked files
SH256 hash:
4c9b6b07954c73955048fffc9845213a3cc2082f42baad16a6ed90251e8dbc1d
MD5 hash:
58240dc8c834fda4434837b8fa7437a8
SHA1 hash:
3f6d0c228affddfc00bcb35d6864c757753466f3
SH256 hash:
034e3d20aaf1eee5cda4136cb93da8ec6f9a27726805ee4a4d289d0634f21ae1
MD5 hash:
0f45923625bc9a5eae1f0c96b36dd955
SHA1 hash:
66e16bc66e90617b2d7c7930f51b8f0a22796ee0
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments