🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fa3fa91f98deaa01d8378b2645d25be176b66fb6df5bc9dc8462d629fce3d85. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6fa3fa91f98deaa01d8378b2645d25be176b66fb6df5bc9dc8462d629fce3d85
SHA3-384 hash: 5a3da3bd192719d567d91d273992383b48eccf99cc1e81208bc17347711642105281e16c62c740fa3e9ff45257c10749
SHA1 hash: 0f3ff68292fae1b189ea00d2c6b4b6c45621ffed
MD5 hash: c0375790762356a5652719b97a7b5602
humanhash: network-winner-hamper-cola
File name:zzJG_2.zip
Download: download sample
Signature Kimsuky
File size:4'657 bytes
First seen:2025-02-09 09:09:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 96:lQIKwQjSqCfuHILVE2PjgiTqSCKF9U+WIOGgbjlbvuEZ+UxeBI:uxgqCfZVjgiTsKgXIqjVvZZ+Ur
TLSH T151A17E817243099BEA3F5FB660D46687A27CB3215213A2F4F5AFDA6308A601F505A88C
Magika zip
Reporter JAMESWT_WT
Tags:APT43 forceCopy Kimsuky zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
160
Origin country :
IT IT
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:G3892.tmp
File size:7'541 bytes
SHA256 hash: e73e089165c3fd5ff713d658ded55a9c9f873ec98aba1c7e42f171c5215e1b5f
MD5 hash: 1e9d94d88fdac3c4a0a47a3a1d07e329
MIME type:text/plain
Signature Kimsuky
File name:83972.tmp
File size:1'571 bytes
SHA256 hash: 0930b4fc55767e86d3ca9f4b6a17db64ad1b1d23b6a9f358d78b06bd2216b8b9
MD5 hash: 5fca1117c0e5ee6de3c169eebc903227
MIME type:text/plain
Signature Kimsuky
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
virus
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-02-09 09:07:48 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Checks computer location settings
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Kimsuky

zip 6fa3fa91f98deaa01d8378b2645d25be176b66fb6df5bc9dc8462d629fce3d85

(this sample)

  
Delivery method
Distributed via web download

Comments