MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84382639746a15b8d22e688cc3dd7a30f6fda64f18580348b14c23aa34c8a6cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Worm.Virut


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 84382639746a15b8d22e688cc3dd7a30f6fda64f18580348b14c23aa34c8a6cd
SHA3-384 hash: c1d41aba3abeccc5a7257c59dbc08de4f34eb1d465b5978b8f2c83b3ed0f3b234f13ce34c404189a0a8ce95c6c7863d6
SHA1 hash: 07f561a481c3c542e1ef1a861849b3d27719bca9
MD5 hash: c21d2c14461fb9a798225d33e038f6e0
humanhash: bacon-four-utah-twenty
File name:virussign.com_c21d2c14461fb9a798225d33e038f6e0
Download: download sample
Signature Worm.Virut
File size:142'848 bytes
First seen:2022-07-13 14:54:36 UTC
Last seen:2022-07-13 15:41:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 12da878c5889d860091d0234440c2c8e (1 x Worm.Virut)
ssdeep 3072:44Tn8USECAFetKyAWeWMCLFyWKsuXLbmJKUyofbA9f:44Tn8RjsDBWeWMtFswvW9O
Threatray 13'061 similar samples on MalwareBazaar
TLSH T150D3E6027AE86135E6F22AB16ABDA2900376BC606F31C2CF5346469F1D756D1CC30BB3
TrID 42.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
22.3% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
14.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.1% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter KdssSupport
Tags:exe Worm.Virut


Avatar
KdssSupport
Uploaded with API

Intelligence


File Origin
# of uploads :
2
# of downloads :
216
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
virussign.com_c21d2c14461fb9a798225d33e038f6e0
Verdict:
Suspicious activity
Analysis date:
2022-07-13 23:52:06 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Searching for the window
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
rans.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Deletes shadow drive data (may be related to ransomware)
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Tries to evade debugger and weak emulator (self modifying code)
Writes to foreign memory regions
Yara detected Virut
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 662867 Sample: 3jkqO2dtZK.com_c21d2c14461f... Startdate: 13/07/2022 Architecture: WINDOWS Score: 100 34 ant.trenz.pl 2->34 36 ilo.brenz.pl 2->36 40 Snort IDS alert for network traffic 2->40 42 Multi AV Scanner detection for domain / URL 2->42 44 Antivirus / Scanner detection for submitted sample 2->44 46 4 other signatures 2->46 9 3jkqO2dtZK.exe 1 2->9         started        signatures3 process4 signatures5 48 Tries to evade debugger and weak emulator (self modifying code) 9->48 50 Maps a DLL or memory area into another process 9->50 12 lsass.exe 9->12 injected 15 svchost.exe 9->15 injected 17 conhost.exe 9->17         started        19 20 other processes 9->19 process6 signatures7 52 Writes to foreign memory regions 12->52 21 MpCmdRun.exe 1 12->21         started        23 backgroundTaskHost.exe 12->23 injected 25 backgroundTaskHost.exe 39 25 15->25         started        28 BackgroundTransferHost.exe 13 15->28         started        30 BackgroundTransferHost.exe 13 15->30         started        process8 dnsIp9 32 conhost.exe 21->32         started        38 192.168.2.1 unknown unknown 25->38 process10
Threat name:
Win32.Virus.Virut
Status:
Malicious
First seen:
2015-04-29 06:28:00 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
24 of 25 (96.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
evasion
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Modifies firewall policy service
Unpacked files
SH256 hash:
84382639746a15b8d22e688cc3dd7a30f6fda64f18580348b14c23aa34c8a6cd
MD5 hash:
c21d2c14461fb9a798225d33e038f6e0
SHA1 hash:
07f561a481c3c542e1ef1a861849b3d27719bca9
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Worm.Virut

Executable exe 84382639746a15b8d22e688cc3dd7a30f6fda64f18580348b14c23aa34c8a6cd

(this sample)

  
Delivery method
Distributed via web download

Comments