MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81a9eb444ffc7c5a700d4da6198c2f929d0e312d38667b9d3e29740eccabca3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 81a9eb444ffc7c5a700d4da6198c2f929d0e312d38667b9d3e29740eccabca3f
SHA3-384 hash: dcfc7d274eb2438ae5f3ef9d0ebfc1d762680baa8ef0ca51116ccfff010b70839a64452f23a26bee1f80c4d96de4ce1c
SHA1 hash: dabfb88a8dea9c8c258be021a3d190e145a65847
MD5 hash: fcb76558dbf86a26c4bdd2811d5d06b6
humanhash: batman-sad-earth-zulu
File name:sRjbEZvCFOESXQJ.dll
Download: download sample
File size:724'992 bytes
First seen:2020-04-02 09:15:45 UTC
Last seen:2020-04-02 09:44:24 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 6d3a0c4e8389ff31bf2c232263c1eba0
ssdeep 6144:7QihZtNT7DIs9m6phIGNM0RkjOorkHP7A0WI/+DIvaWx3C/opWemqQu7FAxtS:7QihlvI2arA7w3JW9CMWhA
Threatray 41 similar samples on MalwareBazaar
TLSH 74F4172A660384EBE7753A30E7E60E179941B1D5E4300C8F7A7E9E9C7E90B917C09EC5
Reporter Racco42
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DLL dll 81a9eb444ffc7c5a700d4da6198c2f929d0e312d38667b9d3e29740eccabca3f

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::GetExplicitEntriesFromAclA
COM_BASE_APICan Download & Execute componentsole32.dll::CoAddRefServerProcess
MULTIMEDIA_APICan Play Multimediawinmm.dll::joyGetNumDevs
winmm.dll::midiOutGetNumDevs
winmm.dll::sndPlaySoundA
winmm.dll::timeGetDevCaps
SECURITY_BASE_APIUses Security Base APIadvapi32.dll::GetSecurityDescriptorControl
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA
WIN_BASE_IO_APICan Create Filesversion.dll::GetFileVersionInfoSizeA
WIN_USER_APIPerforms GUI Actionsuser32.dll::CsrBroadcastSystemMessageExW

Comments