MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5eb0794df0be82e3aee984a24dd0197d9d474703d9b4a1a00d8affc99a1a10b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5eb0794df0be82e3aee984a24dd0197d9d474703d9b4a1a00d8affc99a1a10b6
SHA3-384 hash: 710a868b8298377f973908299a5a69662146bc63b5146fe69057d0e7563ec29416f890d358c8ce9aa375d66b6ce89a03
SHA1 hash: 7efbb0371a45901e916e4ae53569c1e4d96ac030
MD5 hash: fa3ad5714de589c2478e28025e7e39a5
humanhash: william-neptune-west-nebraska
File name:5eb0794df0be82e3aee984a24dd0197d9d474703d9b4a1a00d8affc99a1a10b6.dll
Download: download sample
File size:11'264 bytes
First seen:2020-08-27 22:14:15 UTC
Last seen:2020-08-27 22:39:25 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash dae02f32a21e03ce65412f6e56942daa (123 x YellowCockatoo, 60 x CobaltStrike, 44 x JanelaRAT)
ssdeep 192:V/oREE2Zq0qPcy9CKK0cvm8Ye0F4Ldya8JxduQVqvaNuS:ZoRETg0qUEhamLtF1PbduUTx
TLSH A532290693DC0356C9BE063997F3925542B2E6260313DFC71EE4217E89A73D44B793B1
Reporter xme
Tags:sansisc


Avatar
xme
Malicious DLL delivered by and injected into Powershell

Intelligence


File Origin
# of uploads :
2
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
.
a
c
d
E
g
i
l
N
o
r
s
T
u
v
y
z
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Bluteal
Status:
Malicious
First seen:
2020-08-27 22:16:05 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Modifies data under HKEY_USERS
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments