MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e8ab5a3a7188143d0130d5553690a1254a8bae199b24e4dd09e40c8f9361576. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



YoungLotus


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6e8ab5a3a7188143d0130d5553690a1254a8bae199b24e4dd09e40c8f9361576
SHA3-384 hash: 8adf5b9de64af1a97345605bde7ababdf9cdf3190410b790c1190d1963ce8009e84e0bde9c9d8e9119d945a5b8a98119
SHA1 hash: af11e5b6763c232d84648f5ba7e52baf60c3aec2
MD5 hash: 6c07598dd1e69a3cc89babb648ba4752
humanhash: mobile-river-mobile-jig
File name:菲律宾警方发布了:6名中国菜农被当场击毙视频.bat
Download: download sample
Signature YoungLotus
File size:643'072 bytes
First seen:2021-09-22 21:08:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e2afc946bb1a7942e18b4d1a8f444ebd (9 x YoungLotus, 2 x Nitol)
ssdeep 6144:yc5s/L2PwnAFbCDCGkVcscYax9KCEyP3rQCzS:ycKzmwnAFbBGkaNxjQ
Threatray 48 similar samples on MalwareBazaar
TLSH T128D4AE11BECD88F7D54200324DE76B7AFAB6BC183E118A879368FF4EDD71391A51A610
File icon (PE):PE icon
dhash icon 8e9c048080109894 (3 x YoungLotus)
Reporter ActorExpose
Tags:exe younglotus

Intelligence


File Origin
# of uploads :
1
# of downloads :
248
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
菲律宾警方发布了:6名中国菜农被当场击毙视频.bat
Verdict:
No threats detected
Analysis date:
2021-09-22 21:09:28 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Unknown
Detection:
malicious
Classification:
bank.spyw.evad
Score:
68 / 100
Signature
Checks if browser processes are running
Contains functionality to capture and log keystrokes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Tries to evade analysis by execution special instruction which cause usermode exception
Behaviour
Behavior Graph:
Threat name:
Win32.Backdoor.Farfli
Status:
Malicious
First seen:
2021-09-18 05:04:00 UTC
AV detection:
16 of 27 (59.26%)
Threat level:
  5/5
Result
Malware family:
chinese_generic_botnet
Score:
  10/10
Tags:
family:chinese_generic_botnet botnet persistence
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Drops file in Program Files directory
Adds Run key to start application
Enumerates connected drives
Chinese Botnet Payload
Generic Chinese Botnet
Unpacked files
SH256 hash:
6e8ab5a3a7188143d0130d5553690a1254a8bae199b24e4dd09e40c8f9361576
MD5 hash:
6c07598dd1e69a3cc89babb648ba4752
SHA1 hash:
af11e5b6763c232d84648f5ba7e52baf60c3aec2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments