MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 724b24082b064c4857039e906a643153aa4099e35c0d72dd9afcd2eaf574a137. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 724b24082b064c4857039e906a643153aa4099e35c0d72dd9afcd2eaf574a137
SHA3-384 hash: 7267d650406d2b48f6b3ad8d558034526644ddc20139d680a26f8e72e43e341e403fb34fdd03dc7919c170898a0f51c0
SHA1 hash: 6b9a0538692f839affb7d117afd91306c06e7058
MD5 hash: cc96345a3fd91da5bb6b8d219c5c0c6b
humanhash: eighteen-early-jupiter-floor
File name:mport.exe
Download: download sample
File size:14'336 bytes
First seen:2024-12-07 14:34:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash eade841928b743f149366188e35c96e4
ssdeep 384:Lnxwp7PW+gk7AzrYlv5LJ6vfxHVTY6tc4dCecfYsRs51y2Z7Rfmv2:yJu+57OsMfxHVNdCe
TLSH T1D0522ACBDD91DBE4E063CEB052DAAB3BCD3251400D96C967AF84DE74A872251EA2DD04
TrID 43.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
22.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
9.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter Gi7w0rm
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
407
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
mport.exe
Verdict:
No threats detected
Analysis date:
2024-12-07 14:37:54 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
virus gates
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context microsoft_visual_cc
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1570636 Sample: mport.exe Startdate: 07/12/2024 Architecture: WINDOWS Score: 56 10 Antivirus / Scanner detection for submitted sample 2->10 12 Multi AV Scanner detection for submitted file 2->12 6 mport.exe 1 2->6         started        process3 process4 8 conhost.exe 6->8         started       
Threat name:
Win32.Hacktool.Generic
Status:
Suspicious
First seen:
2021-02-27 01:29:48 UTC
File Type:
PE (Exe)
AV detection:
16 of 38 (42.11%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Suspicious use of AdjustPrivilegeToken
System Location Discovery: System Language Discovery
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
724b24082b064c4857039e906a643153aa4099e35c0d72dd9afcd2eaf574a137
MD5 hash:
cc96345a3fd91da5bb6b8d219c5c0c6b
SHA1 hash:
6b9a0538692f839affb7d117afd91306c06e7058
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 724b24082b064c4857039e906a643153aa4099e35c0d72dd9afcd2eaf574a137

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetSystemInfo
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueA
KERNEL32.dll::QueryDosDeviceA

Comments