🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 65ef9ec1b1e27779a1c13b65e8a7f403e24856d448adba98461c2ecb888b5aec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 13


Intelligence 13 IOCs YARA 3 File information Comments

SHA256 hash: 65ef9ec1b1e27779a1c13b65e8a7f403e24856d448adba98461c2ecb888b5aec
SHA3-384 hash: f211aeb068ca5b3664e9d6a85287dbf46c8cc6481d6428dd917c11ddae1d236203e0f1230e9ef2917edb6ad0465f88c5
SHA1 hash: d2ed7ffb2f11ecaf84272ddcce3ed126aa737793
MD5 hash: 5d54953c33a145ee7a52355aa57edbf2
humanhash: mexico-massachusetts-violet-artist
File name:hi.zip
Download: download sample
File size:3'081'216 bytes
First seen:2024-07-05 11:43:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 20c4b14b5064e66d073d37066475b11c
ssdeep 49152:XzOFQEXBWlRuTBgG1q7W7yR6wAc/AKrPcUpu8C35cFzCkPJVIQbdAeQw:D4QPLgBHq7WWMYYKrP9I8CJUC2J+VeQ
Threatray 10 similar samples on MalwareBazaar
TLSH T1E5E53380E1C3C0A9F5AB487486367E27CC0FA974DA75585223C74674DC38B9BB17798B
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
File icon (PE):PE icon
dhash icon 92e0b496a2cada72 (11 x Adware.Generic, 6 x Adware.InstalleRex, 2 x Adware.Yantai)
Reporter lontze7
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
359
Origin country :
GR GR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
65ef9ec1b1e27779a1c13b65e8a7f403e24856d448adba98461c2ecb888b5aec.exe
Verdict:
Malicious activity
Analysis date:
2024-07-05 11:48:19 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
Execution Generic Network Static Stealth Trojan Zpack
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Enabling the 'hidden' option for files in the %temp% directory
Сreating synchronization primitives
Creating a window
Searching for the window
Creating a file
Delayed writing of the file
Moving a file to the %temp% directory
Creating a process from a recently created file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
installer masquerade microsoft_visual_cc packed
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
84 / 100
Signature
Creates an autostart registry key pointing to binary in C:\Windows
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain checking for user administrative privileges
Multi AV Scanner detection for submitted file
Sigma detected: Potentially Suspicious Child Process Of Regsvr32
System process connects to network (likely due to code injection or exploit)
Uses an obfuscated file name to hide its real file extension (double extension)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1468161 Sample: hi.zip.exe Startdate: 05/07/2024 Architecture: WINDOWS Score: 84 52 gibbooc2.com 2->52 56 Multi AV Scanner detection for submitted file 2->56 58 Uses an obfuscated file name to hide its real file extension (double extension) 2->58 60 Sigma detected: Potentially Suspicious Child Process Of Regsvr32 2->60 11 hi.zip.exe 5 26 2->11         started        15 reg.exe 1 1 2->15         started        17 regsvr32.exe 2->17         started        19 2 other processes 2->19 signatures3 process4 file5 44 C:\Users\user\AppData\...\swscale-3.dll._tm, PE32+ 11->44 dropped 46 C:\Users\user\...\swscale-3.dll (copy), PE32+ 11->46 dropped 48 C:\Users\user\AppData\...\postproc-53.dll._tm, PE32+ 11->48 dropped 50 15 other files (none is malicious) 11->50 dropped 70 Found evasive API chain (may stop execution after checking locale) 11->70 21 _tinreg64.exe 3 11->21         started        72 Creates an autostart registry key pointing to binary in C:\Windows 15->72 24 conhost.exe 15->24         started        26 regsvr32.exe 17->26         started        28 WerFault.exe 21 19->28         started        30 conhost.exe 19->30         started        signatures6 process7 file8 42 C:\Users\user\AppData\...\IRenderBmp.dll, PE32 21->42 dropped 32 regsvr32.exe 21->32         started        process9 process10 34 regsvr32.exe 32->34         started        dnsIp11 54 gibbooc2.com 172.111.186.180, 12284, 49715 M247GB United States 34->54 62 System process connects to network (likely due to code injection or exploit) 34->62 64 Found evasive API chain (may stop execution after checking mutex) 34->64 66 Found API chain indicative of debugger detection 34->66 68 Found evasive API chain checking for user administrative privileges 34->68 38 powershell.exe 15 34->38         started        signatures12 process13 process14 40 conhost.exe 38->40         started       
Threat name:
Win32.Trojan.Casdet
Status:
Malicious
First seen:
2024-07-05 11:44:12 UTC
File Type:
PE (Exe)
Extracted files:
7
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: PowerShell
Adds Run key to start application
Checks installed software on the system
Executes dropped EXE
Loads dropped DLL
Unpacked files
SH256 hash:
c0d3364b88165c62448d2ba384771b2ffc176eb65d57a6516cefe3071a8f30e9
MD5 hash:
e2b98e2ec04c2619eae45651714f49d7
SHA1 hash:
fb7b066a05820f3954f591f403e439f7df81f187
SH256 hash:
eb52783b476da720fe0b634aea36e6204155051002dd8671962987f0bdb80b6a
MD5 hash:
a17a507200eba1d56bf56daa646c72cb
SHA1 hash:
765dc5236e4a2ed5877831a58d5b9ac239365f75
SH256 hash:
99871e8417646f8436113c41a09dd52dc1a648830e858bee1295059a9811f894
MD5 hash:
eb6daa0189401309bc0d866013232e00
SHA1 hash:
4c17d2870e6708295d7c92919800db242d68f28c
SH256 hash:
20f3646b36e7ed683485236fa31766551669433fdb233f107cab0b504d0a7d36
MD5 hash:
bb0641e47ce60efb55109a9260552269
SHA1 hash:
7f80d7eda54c52351a99bedddab1523f78b7aa32
SH256 hash:
65ef9ec1b1e27779a1c13b65e8a7f403e24856d448adba98461c2ecb888b5aec
MD5 hash:
5d54953c33a145ee7a52355aa57edbf2
SHA1 hash:
d2ed7ffb2f11ecaf84272ddcce3ed126aa737793
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 65ef9ec1b1e27779a1c13b65e8a7f403e24856d448adba98461c2ecb888b5aec

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_TRUST_INFORequires Elevated Execution (uiAccess:None)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileMappingW
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::GetSystemDirectoryW
KERNEL32.dll::GetFileAttributesW

Comments