🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 861a0b52b3676fb46f4d97699cd3dc02f2f8b5964633491f61a8b22ce9221b1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 861a0b52b3676fb46f4d97699cd3dc02f2f8b5964633491f61a8b22ce9221b1d
SHA3-384 hash: 06e1967c89461a2ec896906d44f9d637308d619962d6040b825c371c73f1dee439c867e0a17c6eeaf3fe96a3b07789c2
SHA1 hash: d2f160bf01a1f7b863188c9b953c197f7b876c7a
MD5 hash: 4e10c8d3d71136e870cf58c0e31db2bc
humanhash: skylark-fourteen-artist-nevada
File name:Skill Assessment.iso
Download: download sample
Signature Lazarus
File size:3'260'416 bytes
First seen:2023-10-14 15:25:18 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:kwG5dutV04/iT5W5pLoJ6qJNPhERaU+d:ZGgJNVARX5ERaUc
TLSH T140E5CF566BB440E4D1B6C13C8AB6D682F7B278950B31CBDF16A5536E2F33AD04D39322
TrID 99.5% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter smica83
Tags:HUN iso Lazarus NukeSped


Avatar
smica83
2023.05.14

Intelligence


File Origin
# of uploads :
1
# of downloads :
199
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Amazon Workspaces.exe
File size:3'207'168 bytes
SHA256 hash: 42f76f37742103bd599a68ef508b515efeb9e9ffddbfdcc43eb552b70b2440e9
MD5 hash: 3ef1892c1a5f1bb056871b7d7e5cd69a
MIME type:application/x-dosexec
Signature Lazarus
File name:Readme.txt
File size:88 bytes
SHA256 hash: 511360fa5ad177842bcffb3e4fc17cda7bb744df592a9dc5f37da86178c1ddfd
MD5 hash: 60641225c17e4146ed2e3253509478d7
MIME type:text/plain
Signature Lazarus
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
context-iso control explorer greyware keylogger lolbin nukesped remote
Threat name:
Win64.Trojan.NukeSped
Status:
Malicious
First seen:
2023-05-12 12:16:15 UTC
File Type:
Binary (Archive)
Extracted files:
30
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Enumerates system info in registry
Suspicious behavior: GetForegroundWindowSpam
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments