MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bfb41ac8df840797e06a7da047dd349e7c4dbf75804f4ef2f3a9eb06daa2e38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6bfb41ac8df840797e06a7da047dd349e7c4dbf75804f4ef2f3a9eb06daa2e38
SHA3-384 hash: e85ddd03bcbcdbe8421ddf2835fbad814d02b549ccb828cb4aa249c921ed977d90bfd88fab5ce5336612e2a0ccf51c0d
SHA1 hash: 43398482bfc3e4e53c5850bf98948c12e4992f39
MD5 hash: 8b356844a3b994cff588a41f44cee34e
humanhash: delaware-undress-fix-vegan
File name:4c837e9256490e2301081570205b26be
Download: download sample
File size:570'880 bytes
First seen:2020-11-17 12:18:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 60d34734e6f441a374a9ec39d547cc08 (1 x Smoke Loader)
ssdeep 12288:uaRA1r1NoHkmjgOknURfM1vgM0uaHvC2T9UmUKYE:uaR+1NoHzgpUFUIuaPC2RUmU
Threatray 6 similar samples on MalwareBazaar
TLSH EFC41210B592C972D01E09F14921E650EA7DB9718BB5DEC33368AF5E7F322D22E76312
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Creating a window
Enabling autorun by creating a file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 12:23:48 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious use of WriteProcessMemory
Drops startup file
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
6bfb41ac8df840797e06a7da047dd349e7c4dbf75804f4ef2f3a9eb06daa2e38
MD5 hash:
8b356844a3b994cff588a41f44cee34e
SHA1 hash:
43398482bfc3e4e53c5850bf98948c12e4992f39
SH256 hash:
a356d92ade4d8d537ea6dfabe765d4cd2ff851faae1d4551b91e50b47aac216f
MD5 hash:
cd8ef9620a6b9ca18a6647d977398606
SHA1 hash:
7d9088ec691191f0f681c9d612957e643cc0ad1f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments