MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e26c4f6f313e5248898a1dbe706ae5b998e12ff16947cb3bfda690ca62612c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pikabot


Vendor detections: 7


Intelligence 7 IOCs YARA 12 File information Comments

SHA256 hash: 7e26c4f6f313e5248898a1dbe706ae5b998e12ff16947cb3bfda690ca62612c4
SHA3-384 hash: 6cf0f449dab0443343d6cd089c0be9d4e41fa68913202e3de5ccd74fef85bd3ee15ce862aa6598c5d7ebe6abcdc65cf4
SHA1 hash: 6103c8d738af54ef058d8b335639b7336603ff45
MD5 hash: 05f6c90eede973d5d8b1c2e487f553c4
humanhash: football-low-quiet-green
File name:housemaidenlyBauckie.cpl
Download: download sample
Signature Pikabot
File size:1'761'516 bytes
First seen:2023-11-06 17:28:52 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash a73413314147b99e8dbc98767d7bcf45 (3 x Pikabot)
ssdeep 49152:98S4/XyHJooFMqTXeUjBMeJOu1SRnC+5K3Sy9ZZ:+S4/CHmoFdL9jlkpu3Si
TLSH T1BF859D607E4CC57DCE6BC772D49E72D520F9E4A0183A0A2F71E8428F2D6ED814539A6F
TrID 32.2% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
20.5% (.EXE) Win64 Executable (generic) (10523/12/4)
12.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
9.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter proxylife
Tags:dll Pikabot

Intelligence


File Origin
# of uploads :
1
# of downloads :
405
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade overlay packed
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Snort IDS alert for network traffic
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1337810 Sample: housemaidenlyBauckie.cpl.dll Startdate: 06/11/2023 Architecture: WINDOWS Score: 52 33 Snort IDS alert for network traffic 2->33 8 loaddll32.exe 1 2->8         started        process3 process4 10 rundll32.exe 8->10         started        13 cmd.exe 1 8->13         started        15 rundll32.exe 8->15         started        17 19 other processes 8->17 signatures5 35 Writes to foreign memory regions 10->35 19 rundll32.exe 13->19         started        21 WerFault.exe 2 16 15->21         started        23 WerFault.exe 16 17->23         started        25 WerFault.exe 16 17->25         started        27 WerFault.exe 17->27         started        29 2 other processes 17->29 process6 process7 31 WerFault.exe 20 16 19->31         started       
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
fb0171055d2089b80be2ba2d9750f918dc36cbb4ac2e32b50b49dc7c0d18408f
MD5 hash:
469ace56c7b2e57be3ccb5a9660c084c
SHA1 hash:
d55eefa666dffcda735084ef9e1d07b7c9773265
SH256 hash:
7e26c4f6f313e5248898a1dbe706ae5b998e12ff16947cb3bfda690ca62612c4
MD5 hash:
05f6c90eede973d5d8b1c2e487f553c4
SHA1 hash:
6103c8d738af54ef058d8b335639b7336603ff45
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:Check_Debugger
Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments