MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98c17bca1113eb80a060620686f0883a7cd0845618ace539bf5025b1d4e478a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Troldesh


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 98c17bca1113eb80a060620686f0883a7cd0845618ace539bf5025b1d4e478a1
SHA3-384 hash: ff23d29bec51a61097646db5002993d820abea0e711c0a47a823cf043f3e36fb48a84c8eae5347e8be590cbd18569cd1
SHA1 hash: ed3c42d7ac10040d28f5aaa796b0a6622e3648f1
MD5 hash: 0194f9a55d01c7cffc6e6da73feeb2e0
humanhash: maine-hydrogen-black-montana
File name:0194f9a55d01c7cffc6e6da73feeb2e0.exe
Download: download sample
Signature Troldesh
File size:1'011'868 bytes
First seen:2020-10-16 14:15:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 24576:+MlX1xXDLIkvMedOubwnrEXLy8uphS7NRc/SB0V386b:jlFxnIf8wnrmW3ORuSBy3rb
TLSH 2D252308BE56F12AC161D8F04A4D815BE71A290F5F0F72631388A6B055773E669FCBEC
Reporter abuse_ch
Tags:exe Ransomware Troldesh

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'553
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.Troldesh
Status:
Malicious
First seen:
2020-10-16 14:17:05 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
98c17bca1113eb80a060620686f0883a7cd0845618ace539bf5025b1d4e478a1
MD5 hash:
0194f9a55d01c7cffc6e6da73feeb2e0
SHA1 hash:
ed3c42d7ac10040d28f5aaa796b0a6622e3648f1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Troldesh

Executable exe 98c17bca1113eb80a060620686f0883a7cd0845618ace539bf5025b1d4e478a1

(this sample)

  
Delivery method
Distributed via web download

Comments