MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51745628d4c34c4b7fc4da7451ef6ca27fdeb2183423be4cc44dc67400184196. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 51745628d4c34c4b7fc4da7451ef6ca27fdeb2183423be4cc44dc67400184196
SHA3-384 hash: 6c514e2fd7d2d0f3a71b64c344925d601fcf9a7a50db5cf03bd7ec4d4d8fac3101a5aaf3f4376243fb44d383d9d182e1
SHA1 hash: f9af77900ed7c676baface97e24cd3fca3427e83
MD5 hash: 099181592db185c539594ecf3053f52d
humanhash: football-ink-video-white
File name:loader.exe
Download: download sample
File size:20'312'080 bytes
First seen:2024-01-03 17:13:40 UTC
Last seen:2024-01-03 21:00:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 243fc301a399348ee0d577e40291124d
ssdeep 393216:FPl7+tvhQO0gdCuE111+FZoQQ1CdjgP1RvtaWjBMrgROI0O9rgtBzb6:GtvhQ4d2+FZoeZ61R1fjWgROIZ9rgtBC
TLSH T13417335EAF503DBAE0D562F15BBD64E000818B90E0D8D6FC290F444C0EBDA5EB65FAB5
TrID 45.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.3% (.EXE) OS/2 Executable (generic) (2029/13)
18.0% (.EXE) Generic Win/DOS Executable (2002/3)
18.0% (.EXE) DOS Executable Generic (2000/1)
Reporter cocaman
Tags:exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
370
Origin country :
CH CH
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed packed themidawinlicense
Result
Verdict:
MALICIOUS
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-12-27 04:27:31 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  7/10
Tags:
themida
Behaviour
Themida packer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_EXE_Packed_Themida
Author:ditekSHen
Description:Detects executables packed with Themida

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments