MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89db78d0750b92b69295f35fd331c4fd5ae9d7388017ddb2ee8fd2c2db4f2660. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 89db78d0750b92b69295f35fd331c4fd5ae9d7388017ddb2ee8fd2c2db4f2660
SHA3-384 hash: a81831f5a0b1704b559c6590ccb05f1f54957584abfea44bb1d40c3a38519cf7607564a2275f392268b41da9ff74c832
SHA1 hash: 95653b1b0ea6ceb1d695c1d815cfb7964de4b28e
MD5 hash: 376e2cfadc60c6aefd46fd1cb55def34
humanhash: nuts-kentucky-one-oklahoma
File name:a1561d655eada14fa448e845d3386b2e
Download: download sample
File size:1'017'152 bytes
First seen:2020-11-17 11:34:50 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 12288:jCI1ywk1Phdo9l37sD9LGuGMbvME3zoak6wWW9RUI8xE/3Neukpdxc:m7BBhd2sD9CulbMEDoZ6nWV8S/3ouadS
TLSH 5D25F1892F14C57BC69E4732A1829239DFE0E642968EDF5E2DACD9F80C773D71C26046
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Threat name:
Win32.Trojan.Bulz
Status:
Malicious
First seen:
2020-11-17 11:36:05 UTC
AV detection:
8 of 28 (28.57%)
Threat level:
  5/5
Verdict:
unknown
Unpacked files
SH256 hash:
89db78d0750b92b69295f35fd331c4fd5ae9d7388017ddb2ee8fd2c2db4f2660
MD5 hash:
376e2cfadc60c6aefd46fd1cb55def34
SHA1 hash:
95653b1b0ea6ceb1d695c1d815cfb7964de4b28e
SH256 hash:
97bcad1e88201adb5d1846dcb85280c34aeb18ae777848c3a5fa3e831c68292c
MD5 hash:
c2a974166706fd29b8278ae9004f7011
SHA1 hash:
c30f05a6a8ee084c6c8feae832a0b2e0288bb18e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments