MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 642cb92847cfa1d2be4386e013bff38c07ecb7bb2f62908131a9b5309ae7942e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 642cb92847cfa1d2be4386e013bff38c07ecb7bb2f62908131a9b5309ae7942e
SHA3-384 hash: 3a403c3c694d2a4c514049084493f2f111ecc7c36b3141eb87501c1c1b3f2fc1d38c5e575e60ca45b146aa4c3e183e63
SHA1 hash: 52fb4e97045e8c4914c1b575e14911f9f0b229eb
MD5 hash: 0039851581e35b48361255533723a77b
humanhash: carpet-fix-robin-ten
File name:SecuriteInfo.com.Trojan.Packed2.48816.23719.20363
Download: download sample
File size:41'472 bytes
First seen:2025-02-21 15:05:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dae02f32a21e03ce65412f6e56942daa (123 x YellowCockatoo, 61 x CobaltStrike, 44 x JanelaRAT)
ssdeep 384:P1GDuI5l9byWyIbr7xVcPGFMhJ2XzyzbnTcsTQ0N7mrjcashMmRIezYtGB5h4eP:PaHQIbmozy3n4sTTN7mrw5ui574
TLSH T149135BE573DC9F93C76A85BA1DA693440DB4E3CBE562E39B084D76022B027D206C77E0
TrID 56.5% (.EXE) Win64 Executable (generic) (10522/11/4)
11.0% (.ICL) Windows Icons Library (generic) (2059/9)
10.9% (.EXE) OS/2 Executable (generic) (2029/13)
10.7% (.EXE) Generic Win/DOS Executable (2002/3)
10.7% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
446
Origin country :
FR FR
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
installer
Result
Verdict:
Malware
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated obfuscated
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.evad
Score:
80 / 100
Signature
Disable Windows Defender real time protection (registry)
Joe Sandbox ML detected suspicious sample
Modifies Windows Defender protection settings
Multi AV Scanner detection for submitted file
Sigma detected: Invoke-Obfuscation Via Stdin
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Windows Binaries Write Suspicious Extensions
Uses cmd line tools excessively to alter registry or file data
Uses shutdown.exe to shutdown or reboot the system
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1621126 Sample: SecuriteInfo.com.Trojan.Pac... Startdate: 21/02/2025 Architecture: WINDOWS Score: 80 93 15.164.165.52.in-addr.arpa 2->93 95 Multi AV Scanner detection for submitted file 2->95 97 Sigma detected: Powershell Defender Disable Scan Feature 2->97 99 Sigma detected: Windows Binaries Write Suspicious Extensions 2->99 101 2 other signatures 2->101 11 loaddll64.exe 1 2->11         started        signatures3 process4 process5 13 rundll32.exe 4 11->13         started        17 cmd.exe 1 11->17         started        19 rundll32.exe 3 11->19         started        21 3 other processes 11->21 file6 91 C:\Users\user\00.bat, ASCII 13->91 dropped 117 Uses shutdown.exe to shutdown or reboot the system 13->117 23 cmd.exe 1 13->23         started        26 shutdown.exe 13->26         started        119 Uses cmd line tools excessively to alter registry or file data 17->119 121 Modifies Windows Defender protection settings 17->121 28 rundll32.exe 3 17->28         started        30 cmd.exe 19->30         started        32 shutdown.exe 19->32         started        34 cmd.exe 21->34         started        36 cmd.exe 21->36         started        signatures7 process8 signatures9 107 Uses cmd line tools excessively to alter registry or file data 23->107 109 Modifies Windows Defender protection settings 23->109 38 cmd.exe 23->38         started        51 10 other processes 23->51 41 conhost.exe 26->41         started        43 cmd.exe 28->43         started        45 shutdown.exe 28->45         started        53 7 other processes 30->53 47 conhost.exe 32->47         started        55 5 other processes 34->55 49 conhost.exe 36->49         started        process10 signatures11 103 Uses cmd line tools excessively to alter registry or file data 38->103 57 reg.exe 38->57         started        105 Modifies Windows Defender protection settings 43->105 60 cmd.exe 43->60         started        62 cmd.exe 43->62         started        64 cmd.exe 43->64         started        68 8 other processes 43->68 66 conhost.exe 45->66         started        70 9 other processes 51->70 72 5 other processes 53->72 74 4 other processes 55->74 process12 signatures13 111 Disable Windows Defender real time protection (registry) 57->111 113 Uses cmd line tools excessively to alter registry or file data 60->113 76 reg.exe 60->76         started        79 reg.exe 62->79         started        81 reg.exe 64->81         started        83 Taskmgr.exe 68->83         started        85 reg.exe 68->85         started        87 reg.exe 68->87         started        89 4 other processes 68->89 process14 signatures15 115 Disable Windows Defender real time protection (registry) 76->115
Threat name:
Win64.Trojan.Sonbokli
Status:
Malicious
First seen:
2025-02-18 19:38:39 UTC
File Type:
PE+ (.Net Dll)
Extracted files:
1
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion evasion privilege_escalation trojan
Behaviour
Checks SCSI registry key(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Access Token Manipulation: Create Process with Token
Enumerates physical storage devices
Checks computer location settings
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender Real-time Protection settings
Modifies Windows Defender notification settings
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
642cb92847cfa1d2be4386e013bff38c07ecb7bb2f62908131a9b5309ae7942e
MD5 hash:
0039851581e35b48361255533723a77b
SHA1 hash:
52fb4e97045e8c4914c1b575e14911f9f0b229eb
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:NET
Author:malware-lu

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 642cb92847cfa1d2be4386e013bff38c07ecb7bb2f62908131a9b5309ae7942e

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments