🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7bb5f6801ab8614fe1b05e43af80ceec144e387d612e96fb043cb62f555ca7c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tmanger


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 7bb5f6801ab8614fe1b05e43af80ceec144e387d612e96fb043cb62f555ca7c0
SHA3-384 hash: 530ece13d41071d94c9aff2da5d5b6063e40b6da693812305ac958e5d607289a148ac4d3dfe978103a57283c286ef5b0
SHA1 hash: d61f168e94940f91dadd3813abcb9f5a78ff8b1a
MD5 hash: 24a9f73af0a8ac5c9e8cd2c60759e4d5
humanhash: don-failed-eleven-south
File name:qkrd.dll
Download: download sample
Signature Tmanger
File size:222'720 bytes
First seen:2021-02-23 13:05:32 UTC
Last seen:2021-02-23 15:16:33 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2dc60b208a7d7de6a3b7f8d56f4c61ee (1 x Tmanger)
ssdeep 6144:GgqsF36tN9TBpJC33qsmT7YlS7Un/fk7n:LqXX9T3O3qxUlSEU
TLSH FC24C04B73A540BBE1B78678C8930A4AE731781107719FAF13A442A51F337E19E7DBA1
Reporter Anonymous
Tags:Tmanger

Intelligence


File Origin
# of uploads :
2
# of downloads :
130
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Binary contains a suspicious time stamp
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 356650 Sample: qkrd.dll Startdate: 23/02/2021 Architecture: WINDOWS Score: 64 26 Multi AV Scanner detection for submitted file 2->26 28 Machine Learning detection for sample 2->28 30 Binary contains a suspicious time stamp 2->30 8 loaddll64.exe 1 2->8         started        process3 process4 10 rundll32.exe 8->10         started        14 rundll32.exe 8->14         started        dnsIp5 24 map.aredoceangroups.shop 158.247.207.104, 443, 49709, 80 FEWPBUS United States 10->24 32 System process connects to network (likely due to code injection or exploit) 10->32 16 cmd.exe 1 10->16         started        18 WerFault.exe 20 9 14->18         started        signatures6 process7 process8 20 conhost.exe 16->20         started        22 chcp.com 1 16->22         started       
Threat name:
Win64.Trojan.Tmanger
Status:
Malicious
First seen:
2021-01-29 21:59:51 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates connected drives
Blocklisted process makes network request
Unpacked files
SH256 hash:
7bb5f6801ab8614fe1b05e43af80ceec144e387d612e96fb043cb62f555ca7c0
MD5 hash:
24a9f73af0a8ac5c9e8cd2c60759e4d5
SHA1 hash:
d61f168e94940f91dadd3813abcb9f5a78ff8b1a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFu
Author:ditekSHen
Description:Detect executables with stomped PE compilation timestamp that is greater than local current time
Rule name:Tmanger_Family_20210223
Author:Rintaro Koike (@nao_sec)
Description:Tmanger Family
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.tmanger

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments