MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f1f7b8e2fc6d9fb748e37d981d6e6cb9e5de29eab70eda27189da4e86bc8c88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LgoogLoader


Vendor detections: 13


Intelligence 13 IOCs YARA File information Comments

SHA256 hash: 4f1f7b8e2fc6d9fb748e37d981d6e6cb9e5de29eab70eda27189da4e86bc8c88
SHA3-384 hash: eaa9841e1822cda9e41e2310206e0181cc71b5e051639961262debb10644f6be14642d38223e8046bd25f529f6e81923
SHA1 hash: 2d226727891f70932bcf983f7d1178613017fa0d
MD5 hash: 0a0777eb7fb8ce59c19632799f34547d
humanhash: jupiter-jupiter-comet-gee
File name:file
Download: download sample
Signature LgoogLoader
File size:1'377'696 bytes
First seen:2022-11-18 03:33:50 UTC
Last seen:2022-11-18 05:36:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 732f4cfdca2cfdac9ecb5aaba5b9fdb5 (2 x LgoogLoader, 1 x RecordBreaker)
ssdeep 24576:vV+7FemCYiNjn3Yvyn8itNHdDQYyXQdEh6K13rzH+WB/vbuB:vV+0YuTuyn8iiAG6krzHg
Threatray 36 similar samples on MalwareBazaar
TLSH T17055DF158BD9C144E8DBB5FE0624D616E694FAC132E2F183A3D4BE942A353E6DC34387
TrID 48.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
16.4% (.EXE) Win64 Executable (generic) (10523/12/4)
10.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.0% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon f0f4fcf4dc9cbca8 (1 x LgoogLoader)
Reporter jstrosch
Tags:exe LgoogLoader signed

Code Signing Certificate

Organisation:woodbowl.com
Issuer:R3
Algorithm:sha256WithRSAEncryption
Valid from:2022-11-15T17:45:44Z
Valid to:2023-02-13T17:45:43Z
Serial number: 04c9a34941d1a2fbae4a4a1ec5df8c927545
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: b32ad0dbc76e15d9c32b36b7bd9bc6d29758aa1d9ec44b93c8b2dc47eb52dc61
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
213
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
file
Verdict:
Suspicious activity
Analysis date:
2022-11-18 03:37:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
DNS request
Launching a process
Sending a custom TCP request
Sending an HTTP GET request
Creating a file in the %temp% directory
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Mustang Panda
Verdict:
Malicious
Result
Threat name:
lgoogLoader
Detection:
malicious
Classification:
troj.evad
Score:
64 / 100
Signature
Allocates memory in foreign processes
Injects a PE file into a foreign processes
Machine Learning detection for sample
Writes to foreign memory regions
Yara detected lgoogLoader
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-11-18 03:34:11 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
15 of 26 (57.69%)
Threat level:
  5/5
Result
Malware family:
lgoogloader
Score:
  10/10
Tags:
family:lgoogloader downloader
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Detects LgoogLoader payload
LgoogLoader
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
4ab5c07816fe779913fa687b2f82e3feaa4e00de05659fe07719b0f057f31e1d
MD5 hash:
c8fa7218b8823ad1ce28ed729d3119d5
SHA1 hash:
2781b2301bc2785462b48db740f8bb3fdfc08493
SH256 hash:
4f1f7b8e2fc6d9fb748e37d981d6e6cb9e5de29eab70eda27189da4e86bc8c88
MD5 hash:
0a0777eb7fb8ce59c19632799f34547d
SHA1 hash:
2d226727891f70932bcf983f7d1178613017fa0d
Malware family:
SmokeLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LgoogLoader

Executable exe 4f1f7b8e2fc6d9fb748e37d981d6e6cb9e5de29eab70eda27189da4e86bc8c88

(this sample)

  
Delivery method
Distributed via web download

Comments