🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 964ec94fd9c6da7090287b6217b7eedd737f4f069fa27613dbfe33260fdfd10e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments 1

SHA256 hash: 964ec94fd9c6da7090287b6217b7eedd737f4f069fa27613dbfe33260fdfd10e
SHA3-384 hash: c0afa8701d4dfb34eda856c305916b274996ad61a139083185717a89b226b5cd324e912f2affcc870a024740eda9b69f
SHA1 hash: 72091774fcd93513f77fbc3d6e72804fb19fb3ff
MD5 hash: d59a0a04abcb38fdb391a09972aa3ff4
humanhash: venus-delta-butter-enemy
File name:964ec94fd9c6da7090287b6217b7eedd737f4f069fa27613dbfe33260fdfd10e
Download: download sample
File size:100'984 bytes
First seen:2021-05-10 08:18:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6cfb934d520c24b0ea46b97fdbfaa3ed
ssdeep 1536:zXH6qouceFkba+Ui1jdCojU9O2kqWnAnPOMVSgf3c7BCt2rhFU:7H5wbaviuT9NPOMVSgf3c7Qt2Y
Threatray 1 similar samples on MalwareBazaar
TLSH A1A38C2137E1D032D4A61930A8A8DB725E7EB4315B7445CB73A8067E5FA03C15B7A36F
Reporter JAMESWT_WT
Tags:2 TOY GUYS LLC signed

Code Signing Certificate

Organisation:2 TOY GUYS LLC
Issuer:Sectigo RSA Code Signing CA
Algorithm:sha256WithRSAEncryption
Valid from:2019-10-21T00:00:00Z
Valid to:2020-10-20T23:59:59Z
Serial number: 818631110b5d14331dac7e6ad998b902
Intelligence: 3 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 81832978b00f1994fe8d4c6f8b82b2d67a8b6a01896eb99265589c03a665df17
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Downloader.Generic
Status:
Suspicious
First seen:
2020-09-05 00:10:12 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
11 of 46 (23.91%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
964ec94fd9c6da7090287b6217b7eedd737f4f069fa27613dbfe33260fdfd10e
MD5 hash:
d59a0a04abcb38fdb391a09972aa3ff4
SHA1 hash:
72091774fcd93513f77fbc3d6e72804fb19fb3ff
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-10 09:05:33 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0001.032] Anti-Behavioral Analysis::Timing/Delay Check GetTickCount
1) [B0009.029] Anti-Behavioral Analysis::Instruction Testing
2) [B0012.001] Anti-Static Analysis::Argument Obfuscation
3) [B0030.002] Command and Control::Receive Data
4) [B0030.001] Command and Control::Send Data
5) [C0002.009] Communication Micro-objective::Connect to Server::HTTP Communication
6) [C0002.012] Communication Micro-objective::Create Request::HTTP Communication
7) [C0002.017] Communication Micro-objective::Get Response::HTTP Communication
8) [C0002.014] Communication Micro-objective::Read Header::HTTP Communication
9) [C0002.005] Communication Micro-objective::Send Data::HTTP Communication
10) [C0002.003] Communication Micro-objective::Send Request::HTTP Communication
11) [C0029.002] Cryptography Micro-objective::SHA1::Cryptographic Hash
12) [C0029] Cryptography Micro-objective::Cryptographic Hash
13) [C0031] Cryptography Micro-objective::Decrypt Data
14) [C0027.009] Cryptography Micro-objective::RC4::Encrypt Data
15) [C0027] Cryptography Micro-objective::Encrypt Data
16) [C0021.004] Cryptography Micro-objective::RC4 PRGA::Generate Pseudo-random Sequence
17) [C0019] Data Micro-objective::Check String
18) [C0026.001] Data Micro-objective::Base64::Encode Data
21) [C0049] File System Micro-objective::Get File Attributes
22) [C0051] File System Micro-objective::Read File
23) [C0052] File System Micro-objective::Writes File
24) [C0007] Memory Micro-objective::Allocate Memory
25) [C0040] Process Micro-objective::Allocate Thread Local Storage
26) [C0038] Process Micro-objective::Create Thread
27) [C0041] Process Micro-objective::Set Thread Local Storage Value
28) [C0018] Process Micro-objective::Terminate Process