MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e7c1579056731a20e447a20bc1b5a02e72bd2aa26a85dcdff687e577f574306. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6e7c1579056731a20e447a20bc1b5a02e72bd2aa26a85dcdff687e577f574306
SHA3-384 hash: 3b27fa8d1df080a1d090c243c51201491b44a576ccf2e9747955de1dc1262d3b856303011824e5be42f9d7ad71c01b9c
SHA1 hash: da67be803bec0c3e271b773c644f961464b57749
MD5 hash: 5634d2c7f774c55f984339f319bd32aa
humanhash: mobile-violet-oxygen-stairway
File name:5634d2c7f774c55f984339f319bd32aa.dll
Download: download sample
File size:8'192 bytes
First seen:2022-03-12 06:58:37 UTC
Last seen:2022-03-12 08:43:02 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 96:asmv9FxYXL1GNINGeMwjWcxJFuiZOCCCw8P+8:as6rMCcxJ7hw828
Threatray 10 similar samples on MalwareBazaar
TLSH T145F1196FF24BC1EEEC0614B3150FA9361A55716A17DCDD3E8D04D5AFA7633906826802
Reporter abuse_ch
Tags:dll

Intelligence


File Origin
# of uploads :
2
# of downloads :
168
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 587887 Sample: CZ5GLH6DlC.dll Startdate: 12/03/2022 Architecture: WINDOWS Score: 23 34 Sigma detected: Suspicious Call by Ordinal 2->34 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Threat name:
Win32.Trojan.Mikey
Status:
Malicious
First seen:
2022-03-12 06:59:06 UTC
File Type:
PE (Dll)
AV detection:
13 of 42 (30.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
6e7c1579056731a20e447a20bc1b5a02e72bd2aa26a85dcdff687e577f574306
MD5 hash:
5634d2c7f774c55f984339f319bd32aa
SHA1 hash:
da67be803bec0c3e271b773c644f961464b57749
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DLL dll 6e7c1579056731a20e447a20bc1b5a02e72bd2aa26a85dcdff687e577f574306

(this sample)

  
Delivery method
Distributed via web download

Comments