MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8db272ea1100996a8a0ed0da304610964dc8ca576aa114391d1be9d4c5dab02e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 8db272ea1100996a8a0ed0da304610964dc8ca576aa114391d1be9d4c5dab02e
SHA3-384 hash: a27aa0ab9eb4b70d7665adcd9dd098e85d24374b0e6781cf63df7809513be620b9ef817181cb2da9b0e085a4d76a040c
SHA1 hash: 5f4fbd57319bd0d2df31131e864fdda9590a652d
MD5 hash: f337e8beb02dade38a860c2025de439b
humanhash: finch-low-zebra-robert
File name:f337e8beb02dade38a860c2025de439b
Download: download sample
Signature Lazarus
File size:148'480 bytes
First seen:2020-09-29 11:48:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 61d70120d1b7f0bafe794f8d3515ef23 (1 x Lazarus)
ssdeep 3072:Oo/r+KKdkFJniShbZXRiivLcXfA4uTs/gX/ba5M5QFTiTuJG9Y:D6KF3niShbRX0FuTs/gPba5UUJN
TLSH CAE36A8672A514FAD417E23ACAA34A53F3B3745143299BDF036086B52F137D1BE3A352
Reporter dave_m
Tags:Lazarus

Intelligence


File Origin
# of uploads :
1
# of downloads :
168
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.NukeSped
Status:
Malicious
First seen:
2020-05-14 22:26:00 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
8db272ea1100996a8a0ed0da304610964dc8ca576aa114391d1be9d4c5dab02e
MD5 hash:
f337e8beb02dade38a860c2025de439b
SHA1 hash:
5f4fbd57319bd0d2df31131e864fdda9590a652d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments