MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e9d81a4ddccdf9d0b6d6b940c2091b2f2b89d360244e61256b19db94904b100. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Neutrino


Vendor detections: 3


Intelligence 3 IOCs YARA 3 File information Comments

SHA256 hash: 5e9d81a4ddccdf9d0b6d6b940c2091b2f2b89d360244e61256b19db94904b100
SHA3-384 hash: 96ddf3dfbff369a538591e141fadd9b1b5609635fbd7a2859123be0bb2f51f092d1417ba6f28da325a4d8cfc2d024ef9
SHA1 hash: f59b16bd6ba19d0e7a96dfd0613f9d33b345672b
MD5 hash: 2b95949aed6f8b58fcbcb487370f26c7
humanhash: quebec-music-georgia-enemy
File name:SecuriteInfo.com.Pakes3_c.ARPK.25295.12387
Download: download sample
Signature Neutrino
File size:252'928 bytes
First seen:2020-04-21 21:52:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d0bc6d133ea7e2ad444fefe91bb3eff4 (1 x Neutrino)
ssdeep 3072:00PopqR1XuHVlty5lYTpFHCYL0OA6W6hhAQd9uAH/KdblXYypWI+bZk9PIIQt:00CqRZuH1yc99CftAANlXY8WI+bZk9gt
Threatray 71 similar samples on MalwareBazaar
TLSH 57342832B2A0D0E3C4A11775CD5B8DF54F25ED2B95704147BA843EFBBAF01A1C9262E9
Reporter SecuriteInfoCom
Tags:Neutrino

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_jimmy_g0
Author:Slavo Greminger, SWITCH-CERT
Reference:https://securelist.com/jimmy-nukebot-from-neutrino-with-love/81667/
Rule name:win_neutrinobot_g2
Author:Slavo Greminger, SWITCH-CERT
Rule name:win_neutrino_g1
Author:Slavo Greminger, SWITCH-CERT

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Neutrino

Executable exe 5e9d81a4ddccdf9d0b6d6b940c2091b2f2b89d360244e61256b19db94904b100

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
ole32.dll::CreateStreamOnHGlobal
MULTIMEDIA_APICan Play MultimediaAVIFIL32.dll::AVIStreamGetFrameClose
AVIFIL32.dll::AVIStreamGetFrame
AVIFIL32.dll::AVIStreamGetFrameOpen
MSVFW32.dll::DrawDibOpen
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::PrivilegeCheck
SHELL_APIManipulates System ShellSHELL32.dll::SHQueryRecycleBinA
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::OpenProcessToken
ADVAPI32.dll::OpenThreadToken
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::FillConsoleOutputAttribute
KERNEL32.dll::FillConsoleOutputCharacterA
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetConsoleCursorPosition
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleScreenBufferInfo
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileA
VERSION.dll::GetFileVersionInfoSizeA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::OpenClipboard
USER32.dll::CreateWindowExA

Comments