MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 831ba6efa4a49eb1c7ff749fe442b393c5a614f383bf1efb52512a183b4362fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 831ba6efa4a49eb1c7ff749fe442b393c5a614f383bf1efb52512a183b4362fc
SHA3-384 hash: f0395cb3141b8dc4ab4b309b1a7719622c8886812b949c97044be686d5adfb3c2833adadd800de52f7283c26e7bc2c5d
SHA1 hash: ed4edf065a58c212d1dc485ed5e3c4c0bd7f40e2
MD5 hash: 81388e478dfb4bcba683886bb39c5b15
humanhash: zebra-golf-high-sweet
File name:831ba6efa4a49eb1c7ff749fe442b393c5a614f383bf1efb52512a183b4362fc
Download: download sample
File size:2'498'048 bytes
First seen:2020-08-25 14:13:09 UTC
Last seen:2020-08-25 15:05:59 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash baa93d47220682c04d92f7797d9224ce (139 x RiseProStealer, 26 x Xtrat, 18 x CoinMiner)
ssdeep 49152:obo8DWqzEKDlN2XbaF2QRKtfpecbtbUy/z71po43+NR:o0OWqzlDmLaF2+Ktfpe4QyrhpD38
Threatray 1 similar samples on MalwareBazaar
TLSH 14C53355FDD49AF1CF435EF88B5496AD321AD0618F1F03894388BF559A23E8E1B22372
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
2
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 276986 Sample: Y2S2RZ6Ds2 Startdate: 25/08/2020 Architecture: WINDOWS Score: 56 13 Multi AV Scanner detection for submitted file 2->13 15 PE file contains section with special chars 2->15 6 loaddll64.exe 1 2->6         started        process3 process4 8 rundll32.exe 6->8         started        11 rundll32.exe 6->11         started        signatures5 17 Tries to detect virtualization through RDTSC time measurements 8->17
Threat name:
Win64.Trojan.Casdet
Status:
Malicious
First seen:
2020-08-19 00:36:00 UTC
File Type:
PE+ (Dll)
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks BIOS information in registry
Checks BIOS information in registry
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments