MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b021b996b65f29cae4896c11d3a31874e2d5c4ce8a7a212c8bedf7dcae0f8ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ShikataGaNai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 7b021b996b65f29cae4896c11d3a31874e2d5c4ce8a7a212c8bedf7dcae0f8ae
SHA3-384 hash: fd125567c7e420fd0c5a49869cedad67a636406ad8bb04903d776fb649e80e9b2e345f4ba55c501b0d428c8fadcd2f91
SHA1 hash: 336a334cd6f1263d3d36985a6a7dd15a4cf64cd9
MD5 hash: ab13d611d84b1a1d9ffbd21ac130a858
humanhash: nine-cardinal-mirror-oscar
File name:cs_maltest.exe
Download: download sample
Signature ShikataGaNai
File size:139'338 bytes
First seen:2022-03-09 11:40:03 UTC
Last seen:2023-10-06 01:31:31 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 481f47bbb2c9c21e108d65f52b04c448 (257 x Meterpreter, 93 x Metasploit, 33 x ShikataGaNai)
ssdeep 1536:IcfYLvQWF/CdDYn7O/Vn0Q8Mb+KR0Nc8QsECIgM7q39:FQLoW9Cmn7Ot0ne0Nc8QsEpm9
TLSH T1BDD39D86F580C825C0A112794E72E6B95634BCA93D11C29A76DCFFEFFFF1490161238A
dhash icon 17332b33b28e4d33 (1 x ShikataGaNai)
Reporter JAMESWT_WT
Tags:exe ShikataGaNai

Intelligence


File Origin
# of uploads :
2
# of downloads :
269
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
cs_maltest.exe
Verdict:
No threats detected
Analysis date:
2018-11-21 01:40:54 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Metasploit
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Metasploit Payload
Behaviour
Behavior Graph:
Threat name:
Win32.Backdoor.Meterpreter
Status:
Malicious
First seen:
2018-05-11 03:32:15 UTC
File Type:
PE (Exe)
Extracted files:
10
AV detection:
39 of 42 (92.86%)
Threat level:
  5/5
Verdict:
malicious
Unpacked files
SH256 hash:
7b021b996b65f29cae4896c11d3a31874e2d5c4ce8a7a212c8bedf7dcae0f8ae
MD5 hash:
ab13d611d84b1a1d9ffbd21ac130a858
SHA1 hash:
336a334cd6f1263d3d36985a6a7dd15a4cf64cd9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Hunting_Rule_ShikataGaNai
Author:Steven Miller
Reference:https://www.fireeye.com/blog/threat-research/2019/10/shikata-ga-nai-encoder-still-going-strong.html
Rule name:Hunting_Rule_ShikataGaNai
Author:Steven Miller
Reference:https://www.fireeye.com/blog/threat-research/2019/10/shikata-ga-nai-encoder-still-going-strong.html

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ShikataGaNai

Executable exe 7b021b996b65f29cae4896c11d3a31874e2d5c4ce8a7a212c8bedf7dcae0f8ae

(this sample)

Comments