MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55306cc15ee985f639e3da4d9756209c2c2a1af901c688c702e8839fe9f780d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Meterpreter


Vendor detections: 2


Intelligence 2 IOCs YARA 2 File information Comments

SHA256 hash: 55306cc15ee985f639e3da4d9756209c2c2a1af901c688c702e8839fe9f780d2
SHA3-384 hash: 797ee0131ae224a3d688914fe798d55edb98ccba72504c037b4651a2dbe90bc76e2e7ce09125630fb895344d3b6f8114
SHA1 hash: 6ee4eff46457c149d4eff2272eb2fc2822816c6f
MD5 hash: a5d7e3d3d1876915270ecc2fae45df95
humanhash: aspen-december-july-robert
File name:billi_4fa79931167d46f7ad70b0e5daf22b23.exe
Download: download sample
Signature Meterpreter
File size:73'802 bytes
First seen:2020-05-03 17:20:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 481f47bbb2c9c21e108d65f52b04c448 (257 x Meterpreter, 93 x Metasploit, 33 x ShikataGaNai)
ssdeep 1536:IAU3H5Cq1AOHA4yhGCJURCt5SW8KsKdB1jveeDEMb+KR0Nc8QsJq39:k3Zp1i3GKULWlDdHjGeoe0Nc8QsC9
Threatray 19 similar samples on MalwareBazaar
TLSH 8573B042E6C40566C162117D67B13AB59E74F5FB2706C2CA768CCDE9EBC2CB052263C7
Reporter JoulK
Tags:exe Meterpreter

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Cobalt_functions
Author:@j0sm1
Description:Detect functions coded with ROR edi,D; Detect CobaltStrike used by differents groups APT
Rule name:Msfpayloads_msf_10
Author:Florian Roth
Description:Metasploit Payloads - file msf.exe
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Meterpreter

Executable exe 55306cc15ee985f639e3da4d9756209c2c2a1af901c688c702e8839fe9f780d2

(this sample)

  
Delivery method
Distributed via web download

Comments