MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4dc302e1f7cf8bdc4983fdf02cf5b13bcd9314bb87953b9c6797187700192665. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4dc302e1f7cf8bdc4983fdf02cf5b13bcd9314bb87953b9c6797187700192665
SHA3-384 hash: 78183a94a57e216805bb0a4093991b9852b218c4e83634f4fda72913778494bc9603a9af5eaf2bd528c765c873410c77
SHA1 hash: e6b4362f843437789b2d7854a390a372a28ffc9a
MD5 hash: 84aa5a019b9c50118a9a42a197358060
humanhash: alanine-mountain-fillet-sierra
File name:maintenanceservice_Win32_DllRelease.dll
Download: download sample
Signature Lazarus
File size:205'824 bytes
First seen:2020-06-22 20:52:10 UTC
Last seen:2020-06-23 09:42:35 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 9cd944566b6ca36a58b18f19d1c26a2c (1 x Lazarus)
ssdeep 3072:Ov9+DMN4NcAkJqDj/IPfit72B/njUF2uX/01cJhBVUPHc:Ov9+DgwXAUyB/QF2CjJhkvc
Threatray 96 similar samples on MalwareBazaar
TLSH CF14070277E58038F1BB17766AB856554A3EBD72D776C4CF6780520E0A30DD1ADB2B32
Reporter James_inthe_box
Tags:dll Lazarus

Intelligence


File Origin
# of uploads :
3
# of downloads :
136
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Nukesped
Status:
Malicious
First seen:
2020-06-05 08:28:00 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
37 of 48 (77.08%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
persistence
Behaviour
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Adds Run entry to start application
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments