MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f81f8ee08a7460a3abd3aed1da137f2824bbdf804951477546a96300bd1e31f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 5f81f8ee08a7460a3abd3aed1da137f2824bbdf804951477546a96300bd1e31f
SHA3-384 hash: ed7770b173683d9f0812de699d91d258c53b5c442d02af38d7da7950660a2525c7195c48b1365facbcb3df5c1650b5b8
SHA1 hash: 5166ff1bb9b4b5d5f0ab460496cf7cc491f81f62
MD5 hash: 8d7db88f1fb9c7308f7368ae65e3f0ef
humanhash: comet-cold-low-sad
File name:file
Download: download sample
File size:16'421'784 bytes
First seen:2022-11-21 18:57:49 UTC
Last seen:2023-08-26 20:53:19 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e569e6f445d32ba23766ad67d1e3787f (262 x Adware.Generic, 41 x RecordBreaker, 24 x RedLineStealer)
ssdeep 393216:Yw/b4RSUZ564kCUTGbNSm1s+JgKKfmUX5fK05/D:YwD4RS54kCUTfm1s+JYJi09
Threatray 5 similar samples on MalwareBazaar
TLSH T1F7F6333FB268653FC96F0B3219734350A8BBBA61B85B8C1E17F4150DCF664602E3B656
TrID 59.6% (.EXE) Inno Setup installer (109740/4/30)
22.5% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
5.7% (.EXE) Win64 Executable (generic) (10523/12/4)
3.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
2.4% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 1270cc92caccd496
Reporter jstrosch
Tags:exe signed

Code Signing Certificate

Organisation:Rocketship Apps, LLC
Issuer:DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Algorithm:sha256WithRSAEncryption
Valid from:2021-12-22T00:00:00Z
Valid to:2022-12-21T23:59:59Z
Serial number: 029776aa5671184c563a2033100df5c6
Intelligence: 3 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: c4cba8207ce200764a7758c370a24eaf33b99c4ed76ef84ac6a59eecb5c48208
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
3
# of downloads :
180
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
file
Verdict:
Suspicious activity
Analysis date:
2022-11-21 18:59:14 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
DNS request
Connecting to a non-recommended domain
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
coinminer overlay packed setupapi.dll shell32.dll virus
Result
Verdict:
MALICIOUS
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
evad.mine
Score:
28 / 100
Signature
Found strings related to Crypto-Mining
Multi AV Scanner detection for submitted file
Obfuscated command line found
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 751137 Sample: file.exe Startdate: 21/11/2022 Architecture: WINDOWS Score: 28 89 Multi AV Scanner detection for submitted file 2->89 91 Found strings related to Crypto-Mining 2->91 12 file.exe 2 2->12         started        16 msiexec.exe 451 138 2->16         started        18 VC_redist.x64.exe 2->18         started        process3 file4 67 C:\Users\user\AppData\Local\Temp\...\file.tmp, PE32 12->67 dropped 93 Obfuscated command line found 12->93 20 file.tmp 2 15 12->20         started        69 C:\Windows\System32\vcruntime140_1.dll, PE32+ 16->69 dropped 71 C:\Windows\System32\vcruntime140.dll, PE32+ 16->71 dropped 73 C:\Windows\System32\vcomp140.dll, PE32+ 16->73 dropped 75 45 other files (none is malicious) 16->75 dropped 24 VC_redist.x64.exe 18->24         started        signatures5 process6 dnsIp7 83 65.9.86.115, 443, 49706 AMAZON-02US United States 20->83 85 d2l7sw81k13yby.cloudfront.net 65.9.86.23, 443, 49691, 49694 AMAZON-02US United States 20->85 87 3 other IPs or domains 20->87 53 C:\Users\user\...\vc_redist.x64.exe (copy), PE32 20->53 dropped 55 C:\Users\user\AppData\Local\...\is-U0MIN.tmp, PE32 20->55 dropped 57 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 20->57 dropped 59 C:\Users\user\AppData\...\PEInjector.dll, PE32 20->59 dropped 26 vc_redist.x64.exe 3 20->26         started        29 VC_redist.x64.exe 24->29         started        file8 process9 file10 61 C:\Windows\Temp\...\vc_redist.x64.exe, PE32 26->61 dropped 31 vc_redist.x64.exe 71 26->31         started        63 C:\Users\user\AppData\Local\...\wixstdba.dll, PE32 29->63 dropped 34 VC_redist.x64.exe 29->34         started        process11 file12 79 C:\Windows\Temp\...\VC_redist.x64.exe, PE32 31->79 dropped 81 C:\Windows\Temp\...\wixstdba.dll, PE32 31->81 dropped 36 VC_redist.x64.exe 30 18 31->36         started        39 VC_redist.x64.exe 34->39         started        process13 file14 51 C:\ProgramData\...\VC_redist.x64.exe, PE32 36->51 dropped 41 VC_redist.x64.exe 36->41         started        43 VC_redist.x64.exe 39->43         started        process15 file16 46 VC_redist.x64.exe 41->46         started        65 C:\Windows\Temp\...\wixstdba.dll, PE32 43->65 dropped process17 file18 77 C:\Windows\Temp\...\wixstdba.dll, PE32 46->77 dropped 49 VC_redist.x64.exe 46->49         started        process19
Threat name:
Win32.Trojan.Miner
Status:
Malicious
First seen:
2022-09-13 13:07:00 UTC
File Type:
PE (Exe)
AV detection:
5 of 26 (19.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
a8b41b4a9a14c8f20c8cee01dc48692ef627a8a6fed21de3a6be78ecb24a9e60
MD5 hash:
ba57463c227a8ef616601fc96031ccbd
SHA1 hash:
17bb3dd55e368efd39492dab4fcd3dbd9ad6758e
SH256 hash:
5f81f8ee08a7460a3abd3aed1da137f2824bbdf804951477546a96300bd1e31f
MD5 hash:
8d7db88f1fb9c7308f7368ae65e3f0ef
SHA1 hash:
5166ff1bb9b4b5d5f0ab460496cf7cc491f81f62
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 5f81f8ee08a7460a3abd3aed1da137f2824bbdf804951477546a96300bd1e31f

(this sample)

  
Delivery method
Distributed via web download

Comments