🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8aa57051e2d9b8d7398e47b5cdabd32df0b28696a32d1d44a8bb6b463b1f3ddb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RecordBreaker


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 8aa57051e2d9b8d7398e47b5cdabd32df0b28696a32d1d44a8bb6b463b1f3ddb
SHA3-384 hash: 22af59dfbd553ac09e7d9b28d82d17d69edec4e30941520a70c3a1ceaca00e076744b14e6aa3cda035af86f0a5ce3c4f
SHA1 hash: fdfa445f23c791606625d6d49e4a0fc42c42f3ba
MD5 hash: 9c4cb4328e1059cd2d304c51cf30d13c
humanhash: harry-texas-maryland-yankee
File name:Softiwe_Download.rar
Download: download sample
Signature RecordBreaker
File size:6'545'375 bytes
First seen:2022-11-10 17:09:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 2022
ssdeep 98304:WbCO8lrOEEBDp29pPXtrkemFgHu16bPjfBVxRwJKtyW8jmtBWSCYuNLJRB:SjtjQ9B9rMOhbfBgfjmtEDh
TLSH T1B46633A3F49B676B39A3F1A42453896F3574FFFB817E491773804818444BCADED0182A
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter crep1x
Tags:2022 pw-2022 Raccoon rar recordbreaker

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://167.235.134.14/ https://threatfox.abuse.ch/ioc/1001887/

Intelligence


File Origin
# of uploads :
1
# of downloads :
206
Origin country :
FR FR
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:kerneld.v64
File size:34'648 bytes
SHA256 hash: 27375351b4a723465f937866f0ffc86e8e612b093673ee25ccf0b7ea803f888f
MD5 hash: e906554453d39a3352051589021054bf
MIME type:application/x-dosexec
Signature RecordBreaker
File name:INIT
File size:1'536 bytes
SHA256 hash: d9c26d06522003c59bb87a10aa137b63461fcaa7ba4e8735f240236b811fb950
MD5 hash: 31cc501cbf8f075038601fc356bac43b
MIME type:application/octet-stream
Signature RecordBreaker
File name:storelibir-2.dll
File size:282'448 bytes
SHA256 hash: 833cdbcac5781d350af6939422c770b5194de1bc0cc1bbd38cd929256f440bbf
MD5 hash: ffb6b65a71232e4b692cb33af2d0cdf8
MIME type:application/x-dosexec
Signature RecordBreaker
File name:lang_aa.txt
File size:140'425 bytes
SHA256 hash: c8abfc11a1aac9d227e0f40dd09e3f3dd5bdff493e6fddc94006c60336210172
MD5 hash: 7e9d90c45134ea0b8877170966054545
MIME type:text/plain
Signature RecordBreaker
File name:lang_ru.txt
File size:147'865 bytes
SHA256 hash: 203960e917c48f42820301f32d3b03b610bb67ca5cc2e0260cecf3d607b9327c
MD5 hash: 6ef67b741e35eba141691cb813f6c67e
MIME type:text/plain
Signature RecordBreaker
File name:kerneld.ia64
File size:107'752 bytes
SHA256 hash: 937e69ab76b4153e554269f8258bbef3b81ed6d16b9ae7f49caa6d31bb1a0746
MD5 hash: 4a7e44fbc1ad1a68b14ff7e6e0aa1fe9
MIME type:application/x-dosexec
Signature RecordBreaker
File name:storelib.dll
File size:163'680 bytes
SHA256 hash: 6b29cad1f6da51f45b7164758a16328eaac9f31021e9172dd3d2f1d0d672da99
MD5 hash: aedf4928d0ed444609abcaab5d8ef334
MIME type:application/x-dosexec
Signature RecordBreaker
File name:storelibir.dll
File size:266'048 bytes
SHA256 hash: 5f5ebabf5143c8afcbaa4eff5e92af251ae483acd3a9ddddd2f743ba07e54019
MD5 hash: 6fcca15d63300917af99a4c4af4f019f
MIME type:application/x-dosexec
Signature RecordBreaker
File name:Softiwe Download.exe
File size:6'516'736 bytes
SHA256 hash: 8fb50a574fd1aa8828c17c9aee81ba2b08a435290eca3f2830e5a41d65199b52
MD5 hash: d09f24c0a05c276738452a9603749979
MIME type:application/x-dosexec
Signature RecordBreaker
Vendor Threat Intelligence
Gathering data
Result
Malware family:
raccoon
Score:
  10/10
Tags:
family:raccoon botnet:d2f643fdb867ca6beffc12549d6afb13 discovery spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Loads dropped DLL
Reads user/profile data of web browsers
Downloads MZ/PE file
Raccoon
Malware Config
C2 Extraction:
http://167.235.134.14/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RecordBreaker

rar 8aa57051e2d9b8d7398e47b5cdabd32df0b28696a32d1d44a8bb6b463b1f3ddb

(this sample)

  
Dropping
Raccoon
  
Delivery method
Distributed via web download

Comments