MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6399814e06253b852792dccb2e02cd468233cf5ada2ed39e5f7202e8d24f8901. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 6399814e06253b852792dccb2e02cd468233cf5ada2ed39e5f7202e8d24f8901
SHA3-384 hash: 0b88021faf34327b868bd4a9e7718ba2157f96bb360f2949c7e4ecf46cf6eb38c4483fb19c16e1942acdb8b962071057
SHA1 hash: da030d0057a11cde156f5b1387c646cd4ce03ecf
MD5 hash: 196509d1713397e7cbe0c7c9ed5bb783
humanhash: oscar-angel-nitrogen-spring
File name:196509d1713397e7cbe0c7c9ed5bb783.exe
Download: download sample
File size:6'387'609 bytes
First seen:2022-03-09 15:18:17 UTC
Last seen:2022-03-09 17:26:37 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d1de500e42d2702177623521d4e86120
ssdeep 98304:asWe3YPq/i1vRMRSEzk6OkSrxwIDspP+2v1MbogKWYtgSNPZQL0nhqe6AMRombvM:/x3Iq/svCReZqkMP+iR/WZSlZbAPHo/
Threatray 4 similar samples on MalwareBazaar
TLSH T125563377E237824DE0BE42B153551BA7B865F507063CD6260F4AFFAC7C37A908669382
File icon (PE):PE icon
dhash icon 0814b2b2b2320c10
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
187
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
DNS request
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug expand.exe overlay packed shell32.dll
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 586197 Sample: HXvmLIbfn8.exe Startdate: 09/03/2022 Architecture: WINDOWS Score: 48 15 Multi AV Scanner detection for submitted file 2->15 6 HXvmLIbfn8.exe 2 2->6         started        process3 process4 8 WerFault.exe 20 9 6->8         started        11 conhost.exe 6->11         started        file5 13 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 8->13 dropped
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2022-03-09 08:20:42 UTC
File Type:
PE+ (Exe)
Extracted files:
3
AV detection:
8 of 42 (19.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
6399814e06253b852792dccb2e02cd468233cf5ada2ed39e5f7202e8d24f8901
MD5 hash:
196509d1713397e7cbe0c7c9ed5bb783
SHA1 hash:
da030d0057a11cde156f5b1387c646cd4ce03ecf
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 6399814e06253b852792dccb2e02cd468233cf5ada2ed39e5f7202e8d24f8901

(this sample)

  
Delivery method
Distributed via web download

Comments