MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 733036ae8101048351d1cf684fe1bc02c1cf7a70725a470bec7cbd59a602738b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.ExtenBro


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 733036ae8101048351d1cf684fe1bc02c1cf7a70725a470bec7cbd59a602738b
SHA3-384 hash: 69fd02e8c96aacfe1b16821f89cb548bebab9317c30fde8a0e1c33de05b8ef0b56c2199031c06a59eb2727ac3734da06
SHA1 hash: f23a8bc93d2fa26eae7e4ff6df8224c3868ad478
MD5 hash: 641ee46feae86010e3672f553ab4c282
humanhash: tennis-earth-hydrogen-cola
File name:733036ae8101048351d1cf684fe1bc02c1cf7a70725a470bec7cbd59a602738b
Download: download sample
Signature Adware.ExtenBro
File size:2'914'989 bytes
First seen:2020-06-10 11:55:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4d17be67c8d0394c5c1b8e725359ed89 (5 x Adware.Generic, 4 x njrat, 3 x NanoCore)
ssdeep 49152:jmSaNsCJiKU0s4UOmnX1HYe8kDSt2BMQikKYBGsj11gRntD4RA:iSMsewfOmX14esCBNJJ+t82
Threatray 96 similar samples on MalwareBazaar
TLSH 18D533DA7750918BFF28FFF0A4BFAE1CA8A5C0CE5B2430471B0A8435CFA9950D653596
Reporter JAMESWT_WT
Tags:Adware.ExtenBro

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-10 11:33:22 UTC
File Type:
PE (Exe)
Extracted files:
151
AV detection:
28 of 31 (90.32%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:njrat evasion persistence trojan
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Modifies service
Adds Run key to start application
Loads dropped DLL
Executes dropped EXE
Modifies Windows Firewall
njRAT/Bladabindi
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments