MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d4b219a3788d8e40bd7083d421e3d7d399a065bd53afb6e74d3fb7ab2bc09bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 4d4b219a3788d8e40bd7083d421e3d7d399a065bd53afb6e74d3fb7ab2bc09bd
SHA3-384 hash: 7c9ddfc2f0b4263c47af6bb753cf8ba8e492951a70bea56313bd65496fd726db332b98343cc4c3602dc8f4fa6aa116d4
SHA1 hash: 730bb6bc5a18470d8eb1751d97e38cbb9ca4ca85
MD5 hash: 1de1cbc246f395ada07f63f44cb53dee
humanhash: emma-william-mars-nineteen
File name:1de1cbc246f395ada07f63f44cb53dee.exe
Download: download sample
File size:2'303'562 bytes
First seen:2020-10-12 05:42:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9d1f0da408c33eebb70b9bfa17b7fddc (4 x njrat, 1 x Jadtre)
ssdeep 49152:toX3yq8XDY2Td2l+xysLqmiuUyKFAMkq9xraNSNzHzn3:toHyq6d2UlcAcTrIS1Tn3
Threatray 30 similar samples on MalwareBazaar
TLSH 36B5331177D4E073C213513118098B72B63DF4756A26928A7FC65F3D3E36AA6CB3AB06
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file in the Windows subdirectories
Deleting a recently created file
Sending a UDP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Unpacked files
SH256 hash:
4d4b219a3788d8e40bd7083d421e3d7d399a065bd53afb6e74d3fb7ab2bc09bd
MD5 hash:
1de1cbc246f395ada07f63f44cb53dee
SHA1 hash:
730bb6bc5a18470d8eb1751d97e38cbb9ca4ca85
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 4d4b219a3788d8e40bd7083d421e3d7d399a065bd53afb6e74d3fb7ab2bc09bd

(this sample)

  
Delivery method
Distributed via web download

Comments