MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7432f3c6b63c6d6635a577ddf71901db45e81da973780504d01523e9b2829582. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 7432f3c6b63c6d6635a577ddf71901db45e81da973780504d01523e9b2829582
SHA3-384 hash: 939c5e838aea523af91b3f836b0f9b8fbc6d353a0601df7b993ecba5325e94dbc084a472de382f3921fbdfc053177f72
SHA1 hash: fe1a15d25c1a9c9a33a68bf53334b6436142c853
MD5 hash: b4fc9286adc69cdb8c9be075659ecef6
humanhash: west-autumn-beer-cola
File name:b4fc9286adc69cdb8c9be075659ecef6.exe
Download: download sample
File size:5'648'354 bytes
First seen:2020-12-05 07:33:36 UTC
Last seen:2020-12-05 09:57:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 98304:l3hvkF59XowzUwCQWFuw/70Jqjsjp2OLolmK57kaINDK3TJhkcC9Bs2v8nnGzM:l3hvkNvUwCQWv0ild57ka2wkcminZ
TLSH A84633F9320F9BAAF221157EB4E168555EB9E8E35450B01C3ADEF2DA1373BC095024E7
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
151
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
.NET source code contains potential unpacker
Machine Learning detection for sample
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-12-05 07:34:07 UTC
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
7432f3c6b63c6d6635a577ddf71901db45e81da973780504d01523e9b2829582
MD5 hash:
b4fc9286adc69cdb8c9be075659ecef6
SHA1 hash:
fe1a15d25c1a9c9a33a68bf53334b6436142c853
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 7432f3c6b63c6d6635a577ddf71901db45e81da973780504d01523e9b2829582

(this sample)

  
Delivery method
Distributed via web download

Comments