MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fa3eaa46c7d8d1f44a2eeca895f802f2aa7a2251bab347ccb765c72d63ccb58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Worm.Virut


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 8fa3eaa46c7d8d1f44a2eeca895f802f2aa7a2251bab347ccb765c72d63ccb58
SHA3-384 hash: 08d9f0c15885b3e747914f876fdb4941338c93470bba13aa85101fa83d8f524d5a9bd5ae8670e387c08e4fc6857bad3d
SHA1 hash: ec2fb593f17a8ae276fca902fadc4b9c8e8758b7
MD5 hash: 73e7f620804c490e1ae7d19392426499
humanhash: triple-robin-west-vegan
File name:a32b2376a88b630c049d0e9c51be4479
Download: download sample
Signature Worm.Virut
File size:52'736 bytes
First seen:2020-11-17 15:52:00 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 356bc7bcc2e348d127074d30fedb7c70 (1 x Worm.Virut)
ssdeep 1536:IlztMQ9i6KIyuroxhqtyT/es4ffJZgRks1j:+tMfErKqtyT2s4ffJB8j
TLSH C5339D01A7A9403FE5925B70A668DB21C67A71301F2C27CFE26026896CFD7E4BC35B53
Reporter seifreed
Tags:Worm.Virut

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
DNS request
Sending a custom TCP request
Unauthorized injection to a browser process
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Virus.Virut
Status:
Malicious
First seen:
2020-11-17 15:57:54 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Unpacked files
SH256 hash:
8fa3eaa46c7d8d1f44a2eeca895f802f2aa7a2251bab347ccb765c72d63ccb58
MD5 hash:
73e7f620804c490e1ae7d19392426499
SHA1 hash:
ec2fb593f17a8ae276fca902fadc4b9c8e8758b7
SH256 hash:
5ce29f966e36bd4129dc9b4a2abb5b23a8419e2e45c7eb9c2a216a62fa98e235
MD5 hash:
b7e85898bc4588ec789af2c07ef60251
SHA1 hash:
87a74b2e005ba2201fa32d2d20503c8c0e2228ac
Detections:
win_virut_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments