MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8def74b44c680933668cf383c8d37e72cda62b597cccb4cfe58e6378fa96415b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Berbew


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 8def74b44c680933668cf383c8d37e72cda62b597cccb4cfe58e6378fa96415b
SHA3-384 hash: 371d2711be989e58d14ad27264bfac2fd85612a5bc8a37e8acd93a989c18c020be70f5bb3f18f168526135c1482aa1f3
SHA1 hash: 887645fb92a333f7735cc67c851f2aeca491acee
MD5 hash: e9113d1a5fb616e910f995b13d081699
humanhash: romeo-mississippi-spring-apart
File name:8def74b44c680933668cf383c8d37e72cda62b597cccb4cfe58e6378fa96415b
Download: download sample
Signature Berbew
File size:1'757'184 bytes
First seen:2020-06-03 08:22:12 UTC
Last seen:2020-06-03 09:24:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 26babd76bbb7f9c516a338b0601b4c9f (35 x Berbew)
ssdeep 24576:7Vy7ru+9Arf9rJIrf9r+rf9rJIrf9ru+9Arf9rJIrf9r:Jq39AB9IBKB9IB39AB9IB
Threatray 33 similar samples on MalwareBazaar
TLSH 6D858CB97EF61CCAC6E5F9B0643A08925D25DC2D1BBCD6995342E09EFB5F00BC4E8601
Reporter raashidbhatt
Tags:Berbew exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Padodor
Status:
Malicious
First seen:
2020-06-04 04:29:30 UTC
AV detection:
47 of 48 (97.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
NTFS ADS
Program crash
Drops file in System32 directory
Loads dropped DLL
Executes dropped EXE
Adds autorun key to be loaded by Explorer.exe on startup
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments