🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b367f4c26ea8c16697cd8b2d41e568a1fa3a6a7909475b7e0850dc38f374dce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Makop


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 7b367f4c26ea8c16697cd8b2d41e568a1fa3a6a7909475b7e0850dc38f374dce
SHA3-384 hash: d42a7c4ee31eb6861fff7a15efa435a35f0ea701e31afe68dcce6d57a252c2654c8d6a2bae52183c15b011074134178e
SHA1 hash: e410d41975b71494ee8d70b375fff4ff0dfdbdcc
MD5 hash: 402af7774c48e1a1a64d4fe70beada2b
humanhash: cola-jersey-lithium-mockingbird
File name:7b367f4c26ea8c16697cd8b2d41e568a1fa3a6a7909475b7e0850dc38f374dce
Download: download sample
Signature Makop
File size:3'232'256 bytes
First seen:2022-10-13 08:37:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2eabe9054cad5152567f0699947a2c5b (2'861 x LummaStealer, 1'312 x Stealc, 1'026 x Healer)
ssdeep 49152:OPW8ZT0ywkxMwK8htCETx5WB2d8adWn5JnX:O+4T0ywkxMDmQ08L3n
Threatray 14'813 similar samples on MalwareBazaar
TLSH T1E7E539EE690561CBD46E137484E7CE426D6D03BA5B1048C3A82D64B97D73FC72ABEC24
TrID 29.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
22.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
20.3% (.EXE) Win32 Executable (generic) (4505/5/1)
9.1% (.EXE) OS/2 Executable (generic) (2029/13)
9.0% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter petikvx
Tags:makop Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
485
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Searching for analyzing tools
Launching a service
Launching cmd.exe command interpreter
Creating a process with a hidden window
Sending a custom TCP request
Launching a process
Creating a file in the Windows subdirectories
Searching for synchronization primitives
Creating a window
Using the Windows Management Instrumentation requests
Changing a file
Creating a file
Moving a recently created file
Deleting volume shadow copies
Forced shutdown of a system process
Creating a file in the mass storage device
Encrypting user's files
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
rans.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Creates files in the recycle bin to hide itself
Creates files inside the volume driver (system volume information)
Deletes shadow drive data (may be related to ransomware)
Deletes the backup plan of Windows
Detected unpacking (changes PE section rights)
Hides threads from debuggers
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
May disable shadow drive data (uses vssadmin)
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Sigma detected: Delete shadow copy via WMIC
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Yara detected Makop ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 722262 Sample: JKKbtWHR60.exe Startdate: 13/10/2022 Architecture: WINDOWS Score: 100 41 Malicious sample detected (through community Yara rule) 2->41 43 Antivirus / Scanner detection for submitted sample 2->43 45 Multi AV Scanner detection for submitted file 2->45 47 5 other signatures 2->47 7 JKKbtWHR60.exe 8 2->7         started        12 wbengine.exe 3 2->12         started        14 vdsldr.exe 2->14         started        16 vds.exe 2->16         started        process3 dnsIp4 39 192.168.2.1 unknown unknown 7->39 31 C:\Users\user\Desktop\...\AQRFEVRTGL.jpg, data 7->31 dropped 33 C:\Users\user\Desktop\LFOPODGVOH.docx, data 7->33 dropped 35 C:\Users\user\Desktop\HMPPSXQPQV.docx, data 7->35 dropped 37 13 other files (1 malicious) 7->37 dropped 59 Detected unpacking (changes PE section rights) 7->59 61 Creates files in the recycle bin to hide itself 7->61 63 Tries to detect sandboxes and other dynamic analysis tools (window names) 7->63 67 5 other signatures 7->67 18 cmd.exe 1 7->18         started        21 JKKbtWHR60.exe 7->21         started        65 Creates files inside the volume driver (system volume information) 12->65 file5 signatures6 process7 signatures8 49 May disable shadow drive data (uses vssadmin) 18->49 51 Deletes shadow drive data (may be related to ransomware) 18->51 53 Deletes the backup plan of Windows 18->53 23 WMIC.exe 1 18->23         started        25 conhost.exe 18->25         started        27 wbadmin.exe 3 18->27         started        29 vssadmin.exe 1 18->29         started        55 Hides threads from debuggers 21->55 57 Tries to detect sandboxes / dynamic malware analysis system (registry check) 21->57 process9
Threat name:
Win32.Trojan.DelShad
Status:
Malicious
First seen:
2022-10-12 14:53:31 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
evasion ransomware trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Interacts with shadow copies
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Drops file in System32 directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks whether UAC is enabled
Checks BIOS information in registry
Identifies Wine through registry keys
Deletes backup catalog
Deletes shadow copies
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Suspicious use of NtCreateUserProcessOtherParentProcess
Unpacked files
SH256 hash:
21385b3de501d0f8a4fae04c38676476242c82e9158196d816c58f24d4a1a658
MD5 hash:
41a4d1ca709c0031d2e1982b4568cca4
SHA1 hash:
59b58773032f74846eda930e44b9c186d49636b5
SH256 hash:
7b367f4c26ea8c16697cd8b2d41e568a1fa3a6a7909475b7e0850dc38f374dce
MD5 hash:
402af7774c48e1a1a64d4fe70beada2b
SHA1 hash:
e410d41975b71494ee8d70b375fff4ff0dfdbdcc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_get_eip
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments