MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 688ed165268b4c50264c6f6a0adfa45ebb873705bd61fbe25e3ccd019b2e9e7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RaccoonStealer
Vendor detections: 6
| SHA256 hash: | 688ed165268b4c50264c6f6a0adfa45ebb873705bd61fbe25e3ccd019b2e9e7c |
|---|---|
| SHA3-384 hash: | d8f0a8925c40134dfad859a130f4d9f8ffec9a4d29157091c6af9bcd676cf4c1b153e1f8ca728bcdc5d82562f07ab8cf |
| SHA1 hash: | 5ec4ca687a853036d61c647d7fc478b8b5ed8513 |
| MD5 hash: | 288fd8b98444147b0ca63e14ab234bdb |
| humanhash: | twenty-equal-snake-wolfram |
| File name: | video29082022.rar |
| Download: | download sample |
| Signature | RaccoonStealer |
| File size: | 16'528'846 bytes |
| First seen: | 2022-08-30 20:19:36 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 196608:lzpjtMSU4gBkvOs8MTTjmyXE1+dD3RCvCfERpk7Fw6JdZLz2th8onznOmj8:ldU4gBgOsfXNXvDhaCfMMw6J3LanzOmQ |
| TLSH | T19DF6338B391075DF255C35046E48E2FC5106B626AAD4BCEB31FADC3226C6BD2CEC6E54 |
| TrID | 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1) 38.4% (.RAR) RAR compressed archive (gen) (5000/1) |
| Reporter | Anonymous |
| Tags: | malware Raccoon RaccoonStealer rar |
Anonymous
Fake YouTube channel (NASA)Intelligence
File Origin
# of uploads :
1
# of downloads :
248
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
File Type:
PDF File
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-08-29 20:37:31 UTC
File Type:
Binary (Archive)
Extracted files:
170
AV detection:
9 of 40 (22.50%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
raccoon
Score:
10/10
Tags:
family:raccoon botnet:763078554532df2068d2ecfbe0fe0001 discovery link pdf spyware stealer
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Malware Config
C2 Extraction:
http://88.119.161.83
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Dropping
Raccoon
Delivery method
Distributed via drive-by
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.