MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 76d36d05b09395fe390b70f948d9d3750a8fc1c4c7b1ce1fb76f86a95583cd05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 76d36d05b09395fe390b70f948d9d3750a8fc1c4c7b1ce1fb76f86a95583cd05
SHA3-384 hash: f1150cbe316e0ced88226dbb83da90ba22c7286761e48305cfd15c9eec254458f246967343c8586de459264068f946e5
SHA1 hash: f2ddf525f9bf9e583cb6e2694e5abfac483660b2
MD5 hash: d18e2a7ed4bb8b745f89a26580b40dd7
humanhash: maryland-mirror-coffee-utah
File name:2.dll
Download: download sample
File size:1'357'312 bytes
First seen:2021-02-08 18:22:15 UTC
Last seen:2021-02-08 20:04:14 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash dae02f32a21e03ce65412f6e56942daa (123 x YellowCockatoo, 60 x CobaltStrike, 44 x JanelaRAT)
ssdeep 1536:wP2n7X/93iQkSxvmHHjK0QbbmYPEVKnYCNHqpWyNlhQZI0tBSOK4iUVd9Q43chTr:wut+xsUSUC2PGXWXTigSjsRkc
Threatray 6 similar samples on MalwareBazaar
TLSH 0755943CADD5623716BAD6BACAF659CBF912754335122C0E54DB03860913F9BBEC201E
Reporter dez_

Intelligence


File Origin
# of uploads :
2
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Creating a window
DHCP request
Changing a file
Sending a UDP request
Creating a file in the %temp% directory
Deleting a recently created file
Launching a process
DNS request
Sending an HTTP GET request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
.NET source code contains very large strings
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Malrep
Status:
Malicious
First seen:
2021-01-13 07:19:16 UTC
File Type:
PE (.Net Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
76d36d05b09395fe390b70f948d9d3750a8fc1c4c7b1ce1fb76f86a95583cd05
MD5 hash:
d18e2a7ed4bb8b745f89a26580b40dd7
SHA1 hash:
f2ddf525f9bf9e583cb6e2694e5abfac483660b2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments