🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 688ed165268b4c50264c6f6a0adfa45ebb873705bd61fbe25e3ccd019b2e9e7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 688ed165268b4c50264c6f6a0adfa45ebb873705bd61fbe25e3ccd019b2e9e7c
SHA3-384 hash: d8f0a8925c40134dfad859a130f4d9f8ffec9a4d29157091c6af9bcd676cf4c1b153e1f8ca728bcdc5d82562f07ab8cf
SHA1 hash: 5ec4ca687a853036d61c647d7fc478b8b5ed8513
MD5 hash: 288fd8b98444147b0ca63e14ab234bdb
humanhash: twenty-equal-snake-wolfram
File name:video29082022.rar
Download: download sample
Signature RaccoonStealer
File size:16'528'846 bytes
First seen:2022-08-30 20:19:36 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 196608:lzpjtMSU4gBkvOs8MTTjmyXE1+dD3RCvCfERpk7Fw6JdZLz2th8onznOmj8:ldU4gBgOsfXNXvDhaCfMMw6J3LanzOmQ
TLSH T19DF6338B391075DF255C35046E48E2FC5106B626AAD4BCEB31FADC3226C6BD2CEC6E54
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter Anonymous
Tags:malware Raccoon RaccoonStealer rar


Avatar
Anonymous
Fake YouTube channel (NASA)

Intelligence


File Origin
# of uploads :
1
# of downloads :
248
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-08-29 20:37:31 UTC
File Type:
Binary (Archive)
Extracted files:
170
AV detection:
9 of 40 (22.50%)
Threat level:
  5/5
Result
Malware family:
raccoon
Score:
  10/10
Tags:
family:raccoon botnet:763078554532df2068d2ecfbe0fe0001 discovery link pdf spyware stealer
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Malware Config
C2 Extraction:
http://88.119.161.83
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
Raccoon
  
Delivery method
Distributed via drive-by

Comments