MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6548bb28396f639c2aef92957b6858d369c7626a881f000d089646811075955f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6548bb28396f639c2aef92957b6858d369c7626a881f000d089646811075955f
SHA3-384 hash: 2928f1ecac4d6dc5aac0f7a1cc6574561f8a408d617517c7bc0aafc63c1281071ca1b02d21227e748f5719bf382f2b4b
SHA1 hash: a7010995512c3be9b2a9ad2e27d9eff1c732f5c5
MD5 hash: 26726bcd43e28e6840b33b69a3064b48
humanhash: blossom-harry-eighteen-winner
File name:26726bcd43e28e6840b33b69a3064b48.exe
Download: download sample
Signature DanaBot
File size:1'007'104 bytes
First seen:2020-05-01 15:31:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5b62c105512826581cec99d13b4b82ab (1 x DanaBot)
ssdeep 24576:CyWLoZE7SQ8P7Z3D7rNG7T7CJSlmWp3EP:IMCB8jpNE7CJMp3E
Threatray 37 similar samples on MalwareBazaar
TLSH D625232437627422D4B2A53DA077E6700A6F7A31A37D416F2F752A1E4E707E08B71B27
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
772
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe 6548bb28396f639c2aef92957b6858d369c7626a881f000d089646811075955f

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::SetSecurityDescriptorSacl
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegSetValueExW

Comments