MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5dcb736bf556729b30654fe97da034c1ccd7471f7587cb82dc33f4aef2248b9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CrimsonRAT


Vendor detections: 9


Intelligence 9 IOCs 1 YARA File information Comments

SHA256 hash: 5dcb736bf556729b30654fe97da034c1ccd7471f7587cb82dc33f4aef2248b9c
SHA3-384 hash: 5eff27bf4f401a300569ab41025e26f66aed66e7ef06b64fd467147b865f73c094405417d8089d36a11b55aef4ffaa03
SHA1 hash: 33e50a79caafb463cec6941269e3e5c764933732
MD5 hash: 4a8fdd5b9b821830f1e4a392abd1b346
humanhash: shade-tennessee-wisconsin-lactose
File name:4a8fdd5b9b821830f1e4a392abd1b346.exe
Download: download sample
Signature CrimsonRAT
File size:10'162'688 bytes
First seen:2021-04-09 08:15:21 UTC
Last seen:2021-04-09 08:56:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'070 x AgentTesla, 20'024 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 768:ddeL9fcciRRxZMFyf/s4hMIengiEGyrE/:dKOVKSphMIigjGyr
Threatray 5 similar samples on MalwareBazaar
TLSH 26A6B745FB98034FDAB7CF3C88612B11D227EEA69932F16E1C543A0DAD316D189E584F
Reporter abuse_ch
Tags:CrimsonRAT exe


Avatar
abuse_ch
CrimsonRAT C2:
185.136.169.155:8761

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.136.169.155:8761 https://threatfox.abuse.ch/ioc/7496/

Intelligence


File Origin
# of uploads :
2
# of downloads :
1'209
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
wardhmrias.exe
Verdict:
Malicious activity
Analysis date:
2021-03-23 09:34:17 UTC
Tags:
trojan rat crimson

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to capture screen (.Net source)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Potential time zone aware malware
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Ransomware.Foreign
Status:
Malicious
First seen:
2021-04-06 01:13:34 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
crimsonrat
Score:
  10/10
Tags:
family:crimsonrat
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Unpacked files
SH256 hash:
5dcb736bf556729b30654fe97da034c1ccd7471f7587cb82dc33f4aef2248b9c
MD5 hash:
4a8fdd5b9b821830f1e4a392abd1b346
SHA1 hash:
33e50a79caafb463cec6941269e3e5c764933732
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments