MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82c8c241387c128a1d00eb9a96ec415ccad32461600441cb9a6c9176cfebd617. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 82c8c241387c128a1d00eb9a96ec415ccad32461600441cb9a6c9176cfebd617
SHA3-384 hash: 12e706bebad02407edebcd2d5f81eb2eb8baf08a46624c8dd5ffa2f6f66a00ee7acb0e17879a6803ee5d55458b9ce804
SHA1 hash: 7bcfd4129d182ee26674ffab6559d6c35534c380
MD5 hash: e1b1415462fbae97238c89946a90f2c6
humanhash: beryllium-asparagus-potato-white
File name:SecuriteInfo.com.BackDoor.Farfli.96.20698.17666
Download: download sample
File size:384'432 bytes
First seen:2020-03-18 09:52:20 UTC
Last seen:2020-03-18 10:04:38 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f197229d03f2fb47bd50b959b5bc269c (21 x CoinMiner, 6 x Blackmoon, 3 x Gh0stRAT)
ssdeep 6144:Wv5zQJVb5p72cHF1ybDFwekh212KhvwIb759QOaBjpaVRPu23E2rJmWjFc94:W4VOiF1WD7kE1dTYOi8V5u23zmWFy4
Threatray 8 similar samples on MalwareBazaar
TLSH BC842297E01C1740CEC60F3A9D27852A94729EEE4F025DE34545BDAAFEF472A2F4885C
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:suspicious_packer_section
Author:@j0sm1
Description:The packer/protector section names/keywords
Reference:http://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high

Comments