MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57aa81416cfdbd76df2a15cb14810f8529ecab0eea978210a4ef3047f35a225e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 57aa81416cfdbd76df2a15cb14810f8529ecab0eea978210a4ef3047f35a225e
SHA3-384 hash: 02a2093829eabf03a8d749a526c193c52d4a045b264fd001e4e8b1ef16f73712b820a828a62b3f3406ccecb26e685702
SHA1 hash: ce40442d708451a0453d390b12d4566bc59345d3
MD5 hash: 8bec74cc5d6a448ec6c38f699d57b5cd
humanhash: island-don-mobile-utah
File name:57aa81416cfdbd76df2a15cb14810f8529ecab0eea978210a4ef3047f35a225e
Download: download sample
File size:2'546'551 bytes
First seen:2020-06-03 09:12:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 98f67c550a7da65513e63ffd998f6b2e (21 x SnakeKeylogger, 13 x MassLogger, 11 x CryptOne)
ssdeep 49152:cYQ3fCMSRSafhRoS8EO8fJhiLa0KHBXZ0Zi1P71xN9co9X5I1WS:ZQ3fCMSRSafhRoS8EO8fJhsa0KhJ0aPe
Threatray 378 similar samples on MalwareBazaar
TLSH 4CC54B12E301D51AE8A384F0151AD7BAAD347F302945A583B3C5BF6D7B702F2AA2571F
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Swisyn
Status:
Malicious
First seen:
2020-06-04 04:29:39 UTC
AV detection:
46 of 48 (95.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
evasion persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Modifies service
Adds Run key to start application
Loads dropped DLL
Executes dropped EXE
Modifies Installed Components in the registry
Modifies WinLogon for persistence
Modifies visiblity of hidden/system files in Explorer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments