MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6feed8191753c80eec2e50df8f8a82450bfef9fd080e85f0f87149d94fb89097. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6feed8191753c80eec2e50df8f8a82450bfef9fd080e85f0f87149d94fb89097
SHA3-384 hash: 45d6e1b35ec128e50c6ef6e68807736a3c16add7b203d04704eedc32a00cf686243f69b065877c8662f91d004bb63743
SHA1 hash: f2a88077516089dc5193c701d2a8a36baeb8444e
MD5 hash: 72a65a62d2abc963708301b2be13d2b0
humanhash: seven-mobile-mango-utah
File name:Act.exe
Download: download sample
File size:1'676'014 bytes
First seen:2021-11-28 16:45:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 027ea80e8125c6dda271246922d4c3b0 (10 x njrat, 7 x DCRat, 5 x DarkComet)
ssdeep 49152:j9ZeRWHMJstBOU06gFsXWik3v2xAy0qeoTk7:6RMjt8U2FsmtuxA5b7
Threatray 1'122 similar samples on MalwareBazaar
TLSH T1F575BC017541877FF8907EF1ACC56E1057FC7D942D10891A76B13E5EF8A60B2BEB0A1A
File icon (PE):PE icon
dhash icon 35353535a5a5a5a5 (1 x FatalRAT)
Reporter tech_skeech
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Act.exe
Verdict:
Malicious activity
Analysis date:
2021-11-28 16:38:22 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
DNS request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware overlay packed zpevdo
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
6feed8191753c80eec2e50df8f8a82450bfef9fd080e85f0f87149d94fb89097
MD5 hash:
72a65a62d2abc963708301b2be13d2b0
SHA1 hash:
f2a88077516089dc5193c701d2a8a36baeb8444e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 6feed8191753c80eec2e50df8f8a82450bfef9fd080e85f0f87149d94fb89097

(this sample)

  
Delivery method
Distributed via web download

Comments