MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4cd1e24f58ebf4ea0b333e8ca2ea88c0d6185477505f5dccd317f37a0c60b293. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4cd1e24f58ebf4ea0b333e8ca2ea88c0d6185477505f5dccd317f37a0c60b293
SHA3-384 hash: c7e253158b843570c57939f205b4b2828d26294fd305d4017d4ed731ab0b537ca0ab450711628ea6dc90191ab091491a
SHA1 hash: decb44156a74523f477ea63902737e22aafd6abc
MD5 hash: e10fcb87b9e6883890acf1865e7659bd
humanhash: nitrogen-mike-kitten-ack
File name:TeamViewer.exe
Download: download sample
File size:2'852'127 bytes
First seen:2020-10-23 18:38:30 UTC
Last seen:2020-10-23 19:47:34 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 49091c5c46d1ed156931ed11f43d3afa (1 x NetWire, 1 x njrat, 1 x Arechclient2)
ssdeep 49152:gY8Q2S0F7vro2cA9EW4Hf/UX7dma2BJ+0tZqXjdn78azp5KrW5Y:h0F7vrV69/kpma2BJ+qYTa4KrW5Y
TLSH 38D53372B6E58133C1B647390DDA6B75A8F8BE9087590FDB63D90A791C314C1123AFE2
Reporter James_inthe_box
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Sending a UDP request
DNS request
Sending a custom TCP request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Sending an HTTP GET request to an infection source
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
84 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Casdet
Status:
Malicious
First seen:
2020-10-15 13:07:22 UTC
File Type:
PE (Exe)
Extracted files:
190
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
99b2ef04be16e7b3cc9b13453399152be0d6b8fbb5ab14fb7561a39199da4fa6
MD5 hash:
0a12f69ce1912654ca09585eb9f2732b
SHA1 hash:
18e34a7bfe9295c10064f5679778464dc9b7dc36
SH256 hash:
08a86ce02e813742e13fe815fd9ce94f474ca2c181d9381fdc31cacc7cc39bf1
MD5 hash:
20bcda61a46f4ea38d286ac6dbee7d53
SHA1 hash:
98e27ce7598ca23e7fbadf1009526270916b6ae4
SH256 hash:
4cd1e24f58ebf4ea0b333e8ca2ea88c0d6185477505f5dccd317f37a0c60b293
MD5 hash:
e10fcb87b9e6883890acf1865e7659bd
SHA1 hash:
decb44156a74523f477ea63902737e22aafd6abc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments