MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54d01da9e6fbd81837ce2800be97a57d750e97e9d02aec4b34341b4c8684ba0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 54d01da9e6fbd81837ce2800be97a57d750e97e9d02aec4b34341b4c8684ba0f
SHA3-384 hash: 803c3242c48b8a8bd72d79b77e832f7b949478f1a73884265aa5d9785cef7e2d94f2cf8933e66722fa251c476ecf9e67
SHA1 hash: ac5aa802506f8128c51e828ca1fc9c6d0a1c1b29
MD5 hash: 596078c194ad525275dbf0787b475c50
humanhash: victor-cardinal-hamper-timing
File name:596078c194ad525275dbf0787b475c50.exe
Download: download sample
File size:5'327'559 bytes
First seen:2023-04-11 12:15:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 49152:A1H4VI6/UGwPVGv8i5aU0Bc21/K2Xd8nGozc30kaZt3DJIHo1fmHp+z:TD8GwVAn29XbozcEX7R
TLSH T1323629C657AA6995D2BB3E37A0B477054F75ED228B5EFB1B1080F5FB1CA6B116C00223
TrID 36.1% (.SCR) Windows screen saver (13097/50/3)
29.0% (.EXE) Win64 Executable (generic) (10523/12/4)
12.4% (.EXE) Win32 Executable (generic) (4505/5/1)
5.6% (.ICL) Windows Icons Library (generic) (2059/9)
5.6% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
248
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
83%
Tags:
obfuscated overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2023-04-10 14:58:06 UTC
File Type:
PE (.Net Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
54d01da9e6fbd81837ce2800be97a57d750e97e9d02aec4b34341b4c8684ba0f
MD5 hash:
596078c194ad525275dbf0787b475c50
SHA1 hash:
ac5aa802506f8128c51e828ca1fc9c6d0a1c1b29
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 54d01da9e6fbd81837ce2800be97a57d750e97e9d02aec4b34341b4c8684ba0f

(this sample)

  
Delivery method
Distributed via web download

Comments