🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 572a124f5665be68eaa472590f3ba75bf34b0ea2942b5fcbfd3e74654202dd09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 572a124f5665be68eaa472590f3ba75bf34b0ea2942b5fcbfd3e74654202dd09
SHA3-384 hash: 2ef16bbd49ed8d3aee7cad5e17b4319b2a2bd5a996046ffeff39c334c6a4c8074ed7d3f9196121e96b15c20427bf8013
SHA1 hash: decb43141699e43a1d27dc2db063e0020f9f33aa
MD5 hash: 149a696472d4a189f5896336ab16cc34
humanhash: sierra-pasta-enemy-fish
File name:572a124f5665be68eaa472590f3ba75bf34b0ea2942b5fcbfd3e74654202dd09.bin
Download: download sample
Signature Lazarus
File size:115'712 bytes
First seen:2021-02-18 01:38:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 565005404f00b7def4499142ade5e3dd (3 x Lazarus)
ssdeep 3072:FHAqeXaeHx9pdpqw6IQIsMF6s3yv7pHOBo:FWXaeHxrvB6X9M33
TLSH 0BB36C5772A030F8E1778639C8656515E3B6B8360B30AF9F03A486665F273919E3EF31
Reporter Arkbird_SOLG
Tags:apt Lazarus

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Sending a custom TCP request
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.NukeSped
Status:
Malicious
First seen:
2020-06-02 02:43:28 UTC
File Type:
PE+ (Exe)
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
572a124f5665be68eaa472590f3ba75bf34b0ea2942b5fcbfd3e74654202dd09
MD5 hash:
149a696472d4a189f5896336ab16cc34
SHA1 hash:
decb43141699e43a1d27dc2db063e0020f9f33aa
Detections:
win_unidentified_077_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments