MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 84545b2db5b60b257083f5ebbc77abbc847724293c378ddf87b1ec58b4d6aaee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Socks5Systemz
Vendor detections: 13
| SHA256 hash: | 84545b2db5b60b257083f5ebbc77abbc847724293c378ddf87b1ec58b4d6aaee |
|---|---|
| SHA3-384 hash: | ec9cd3f54bab507c001398743de82c8f9600b7f27487b2b31bc5df565c46ed5a0346ae1738484f8a549eca00ef1b4810 |
| SHA1 hash: | e590138faf2e66f7f46583c51ffb62c264732009 |
| MD5 hash: | 1afd6b7ef105ad5b4274413058f7a111 |
| humanhash: | minnesota-delaware-oregon-one |
| File name: | 1afd6b7ef105ad5b4274413058f7a111.exe |
| Download: | download sample |
| Signature | Socks5Systemz |
| File size: | 4'813'896 bytes |
| First seen: | 2024-06-13 16:35:15 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 884310b1928934402ea6fec1dbd3cf5e (3'725 x GCleaner, 3'608 x Socks5Systemz, 262 x RaccoonStealer) |
| ssdeep | 98304:m1S8ncpYaAureoRPCs1jpnyWkTpHrykyrRfUlsDzx3dig:iNncpYurens1Fy7TpHrPWslcF |
| Threatray | 422 similar samples on MalwareBazaar |
| TLSH | T1E626334A17D7C936F4396DFE1F6BE063163BA25102F1A028559D81292F931AFE0E3BD1 |
| TrID | 76.2% (.EXE) Inno Setup installer (107240/4/30) 10.0% (.EXE) Win32 Executable Delphi generic (14182/79/4) 4.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.2% (.EXE) Win32 Executable (generic) (4504/4/1) 1.4% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| File icon (PE): | |
| dhash icon | b298acbab2ca7a72 (2'335 x GCleaner, 1'830 x Socks5Systemz, 67 x RedLineStealer) |
| Reporter | |
| Tags: | exe Socks5Systemz |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://ccjqqrm.net/search/?q=67e28dd86f54a728120ffa1d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978f771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6f8cf617c6ec97
cksnksp.net
Unpacked files
18753a0cb65d2b75bd60b82de5ac799c5bc39eab29014c5a57fc04685da72076
2a29d26bf0cbd899c91002cb7548d02b219d9c22df657d3c0e30d55b6f323db5
748acf5e2d770b17c35d1d5643ede9ab1c3a147f65b13dd00ed32fe0bc8c7de0
5927ff34247cc44f8109948a52e943b8f7877e766182113da9cc80e32f5df290
d522bfd80b0a0848a38722586beac3cbe1500c88975bfad821652e3dddd5cd2e
3d2944ecdd0170cb6fac713b7b7a76baad3155394953bed44bb75e8ad5e1b608
c049c5e6a0ec4ba2031d44d9dcb559969db3c9b9c5ba991b0cde2de792653f51
82eeb1ef814f784c6b4a3fb91de8f6ad837ca2a3f42b080e88d1fe935012cf4b
87f8771966eacd833ce2cc81595e72bd47f37e5f8f3a869b6a8198ab0056cc8c
e8dff7348ea1eaa185b0fcf1c882afd621e5155bc3f0452c4f76d4d498862536
7b0ad7b087aa0e4e48bd4554fdf99c8328037689a4e0e666617de4fc93f58ffe
60c18399961ac8eba0a57e61cd04e0614b4875c4ba3bb7403cd6f743f6a4f34b
84545b2db5b60b257083f5ebbc77abbc847724293c378ddf87b1ec58b4d6aaee
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_EXE_Packed_VMProtect |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with VMProtect. |
| Rule name: | MD5_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for MD5 constants |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| SECURITY_BASE_API | Uses Security Base API | advapi32.dll::AdjustTokenPrivileges |
| WIN32_PROCESS_API | Can Create Process and Threads | kernel32.dll::CreateProcessA advapi32.dll::OpenProcessToken kernel32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | kernel32.dll::LoadLibraryA kernel32.dll::GetSystemInfo kernel32.dll::GetCommandLineA |
| WIN_BASE_IO_API | Can Create Files | kernel32.dll::CreateDirectoryA kernel32.dll::CreateFileA kernel32.dll::DeleteFileA kernel32.dll::GetWindowsDirectoryA kernel32.dll::GetFileAttributesA kernel32.dll::RemoveDirectoryA |
| WIN_BASE_USER_API | Retrieves Account Information | advapi32.dll::LookupPrivilegeValueA |
| WIN_REG_API | Can Manipulate Windows Registry | advapi32.dll::RegOpenKeyExA advapi32.dll::RegQueryValueExA |
| WIN_USER_API | Performs GUI Actions | user32.dll::PeekMessageA user32.dll::CreateWindowExA |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.