MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9528b42bbb466390acad5433102227556f428e875afc7a157aca6249c64d32f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9528b42bbb466390acad5433102227556f428e875afc7a157aca6249c64d32f4
SHA3-384 hash: 1c001e96a78e4c4983b6abd75e2960f0b0bd5f203a0c1d76258e03094e7c4ded34cccc1f113c29eb757ab0fdbeaa7222
SHA1 hash: 3cf81aea07d3c0006f264d2bf37ae4a50cf7efa7
MD5 hash: 45a04f354bfdf4a95dc469bb843b961a
humanhash: connecticut-chicken-victor-summer
File name:xyz.rar
Download: download sample
File size:1'728'755 bytes
First seen:2022-04-06 05:11:48 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 49152:v5RErR2CtQaswz/gf+0CV9ml6tCLmQNDLCQgV7JkhiHePQ:BSN2Ta3osfKNNaj7JykeY
TLSH T1438533F2061E3BC1835D17E52951821F6CEA1160D7AEFFE4A7892D291E30BBF7341662
Reporter adm1n_usa32
Tags:rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
235
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
control.exe finger.exe remote.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win64.Trojan.Tiggre
Status:
Malicious
First seen:
2022-03-16 16:20:55 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
16 of 42 (38.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

rar 9528b42bbb466390acad5433102227556f428e875afc7a157aca6249c64d32f4

(this sample)

  
Delivery method
Distributed via web download

Comments