MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69febfcc81d9b79faacbea1468bd0d88508025308a6741d8e2fbd6f7b100c283. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaspberryRobin


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 69febfcc81d9b79faacbea1468bd0d88508025308a6741d8e2fbd6f7b100c283
SHA3-384 hash: 8222b4c6879dee478a5210edf3509d072ef5420bf2343a94da905459923cd52b985d1de188344711c68688d06808ecc4
SHA1 hash: 6589ff833c4325cd6f580f8e33ed10bf0bd86ead
MD5 hash: 9f0c22ed3d7bb9da739c0435a03b8fc0
humanhash: mountain-south-pluto-six
File name:jqplot.hta
Download: download sample
Signature RaspberryRobin
File size:3'190 bytes
First seen:2024-12-21 12:00:39 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 12:mwLhmF6CR5JzyrVbohSCd9gAl5kKMHPtL:m4ivEV8ICn3EL
TLSH T1C461ECD4C6D5C22B2BCC6D33DE58EDC911F6C076D0C5724382B9F94E00DE159C96D444
Magika txt
Reporter aachum
Tags:hta RaspberryRobin


Avatar
iamaachum
https://bewailable.hair/post/IyYgiQ7Ig0

Gets RaspberryRobin from https://969d6a2f.respectfulnesses.makeup/2l5hd077he70d

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
ES ES
Vendor Threat Intelligence
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
56 / 100
Signature
AI detected suspicious sample
Gathers information about network shares
Sigma detected: Suspicious MSHTA Child Process
Tries to detect sandboxes / dynamic malware analysis system (file name check)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1579287 Sample: jqplot.hta Startdate: 21/12/2024 Architecture: WINDOWS Score: 56 31 6t.lc 2->31 33 969d6a2f.respectfulnesses.makeup 2->33 41 Sigma detected: Suspicious MSHTA Child Process 2->41 43 AI detected suspicious sample 2->43 8 mshta.exe 13 2->8         started        signatures3 process4 dnsIp5 37 969d6a2f.respectfulnesses.makeup 104.21.90.205, 443, 49699 CLOUDFLARENETUS United States 8->37 45 Gathers information about network shares 8->45 12 cmd.exe 1 8->12         started        15 cmd.exe 1 8->15         started        signatures6 process7 signatures8 47 Gathers information about network shares 12->47 17 rundll32.exe 12->17         started        20 net.exe 7 12->20         started        23 conhost.exe 12->23         started        25 conhost.exe 15->25         started        27 net.exe 1 15->27         started        29 timeout.exe 1 15->29         started        process9 dnsIp10 39 Tries to detect sandboxes / dynamic malware analysis system (file name check) 17->39 35 6t.lc 147.45.112.248, 443, 49703, 49723 FREE-NET-ASFREEnetEU Russian Federation 20->35 signatures11
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Modifies Internet Explorer settings
System Location Discovery: System Language Discovery
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RaspberryRobin

HTML Application (hta) hta 69febfcc81d9b79faacbea1468bd0d88508025308a6741d8e2fbd6f7b100c283

(this sample)

  
Delivery method
Distributed via web download

Comments