MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88abb1fac4a77edb76cc29e112111e658e66eee14f1eaf19290739ec06b88090. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 88abb1fac4a77edb76cc29e112111e658e66eee14f1eaf19290739ec06b88090
SHA3-384 hash: 433f4b54b0de6ab56530e21ce3f04ac1a5b9999dbcc4b423efa435c5e07479185cc9b13ed28861293a4039b15922014b
SHA1 hash: 60a6c5180127e6ac7cbdfedd1311b7b365c2dad1
MD5 hash: 6ab81ca7dc291dff7bd17d240b1b3036
humanhash: pennsylvania-artist-ack-golf
File name:dzbooster.com_new__lemon.exe.malw
Download: download sample
Signature CobaltStrike
File size:222'720 bytes
First seen:2020-03-27 05:45:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'653 x AgentTesla, 19'464 x Formbook, 12'205 x SnakeKeylogger)
ssdeep 3072:rEr21IsgS23dEUjMUgOjCFfoSr+0m/hbbzDVsdaWprmnx4qNKVbMVvr:rhlUgAMfoSKhbf5sdadnaVoV
Threatray 44 similar samples on MalwareBazaar
TLSH 432402DD7EE46F52D37417FC2076643843B820255018EDA9ECD360DA5AABB4E89E1F07
Reporter ov3rflow1
Tags:Cobalt Strike malw

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments