MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9967989c15c0f7ae425e0980837f6caa91bd9475e97c935ff1ca9e00964423e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SystemBC


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments 1

SHA256 hash: 9967989c15c0f7ae425e0980837f6caa91bd9475e97c935ff1ca9e00964423e6
SHA3-384 hash: 5f6cc2b5cd0c3d4530bf1a8459514f58f915ee05f35bbf552566a255e0251a2359e7bb4737481d9f309cca65a520b662
SHA1 hash: 68830f46c5644e7496d320add7aae88f5ec3f14c
MD5 hash: e80ac907c83884a675b31221c0f9cff0
humanhash: lamp-pip-mountain-potato
File name:e80ac907c83884a675b31221c0f9cff0
Download: download sample
Signature SystemBC
File size:1'751'192 bytes
First seen:2022-09-06 11:47:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c6bac4d534e401091ac0a2139b541daf (1 x SystemBC)
ssdeep 49152:VumnFHeIqTwCtwzfyY2KGeCs6B1r55zYHF4:QmnFHe/TwCt2lGX5R5qHF4
TLSH T100851228E9E895D1CAE014F95B37FB198F7CD10D0427635B2B065672FB72E82346398B
TrID 48.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
16.4% (.EXE) Win64 Executable (generic) (10523/12/4)
10.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.0% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon c0d4d4e8d8d4d4c0 (1 x SystemBC)
Reporter zbetcheckin
Tags:32 exe signed SystemBC

Code Signing Certificate

Organisation:printer.com
Issuer:R3
Algorithm:sha256WithRSAEncryption
Valid from:2022-08-03T03:00:21Z
Valid to:2022-11-01T03:00:20Z
Serial number: 03032d7d1e1edc55f1f0a5b092a81ddb9b25
Thumbprint Algorithm:SHA256
Thumbprint: e8c0bb39848757a248aa7adb2033686de7f685b791d7a1894aab1fa1d990ee5d
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
342
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
systembc
ID:
1
File name:
e80ac907c83884a675b31221c0f9cff0
Verdict:
Malicious activity
Analysis date:
2022-09-06 11:48:29 UTC
Tags:
systembc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
troj.evad
Score:
84 / 100
Signature
Allocates memory in foreign processes
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Self deletion via cmd or bat file
Uses ping.exe to check the status of other devices and networks
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 698139 Sample: 8zluHGpBNe.exe Startdate: 06/09/2022 Architecture: WINDOWS Score: 84 43 Malicious sample detected (through community Yara rule) 2->43 45 Multi AV Scanner detection for submitted file 2->45 47 Machine Learning detection for sample 2->47 7 8zluHGpBNe.exe 4 2->7         started        11 DllHelper.exe 2->11         started        process3 file4 35 C:\Users\user\AppVerif\DllHelper.exe, PE32 7->35 dropped 37 C:\Users\...\DllHelper.exe:Zone.Identifier, ASCII 7->37 dropped 49 Self deletion via cmd or bat file 7->49 51 Uses schtasks.exe or at.exe to add and modify task schedules 7->51 13 DllHelper.exe 7->13         started        16 cmd.exe 1 7->16         started        18 schtasks.exe 1 7->18         started        53 Writes to foreign memory regions 11->53 55 Allocates memory in foreign processes 11->55 57 Injects a PE file into a foreign processes 11->57 20 InstallUtil.exe 11->20         started        signatures5 process6 signatures7 59 Writes to foreign memory regions 13->59 61 Allocates memory in foreign processes 13->61 63 Injects a PE file into a foreign processes 13->63 22 InstallUtil.exe 13->22         started        25 InstallUtil.exe 13->25         started        65 Uses ping.exe to check the status of other devices and networks 16->65 27 PING.EXE 1 16->27         started        29 conhost.exe 16->29         started        31 chcp.com 1 16->31         started        33 conhost.exe 18->33         started        process8 dnsIp9 39 89.22.225.242, 4193, 49758, 49759 INETLTDTR Russian Federation 22->39 41 127.0.0.1 unknown unknown 27->41
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-09-05 21:40:40 UTC
File Type:
PE (Exe)
Extracted files:
27
AV detection:
18 of 40 (45.00%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
systembc
Score:
  10/10
Tags:
family:systembc trojan
Behaviour
Creates scheduled task(s)
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Deletes itself
Loads dropped DLL
Executes dropped EXE
SystemBC
Malware Config
C2 Extraction:
89.22.225.242:4193
195.2.93.22:4193
Unpacked files
SH256 hash:
169ba3fd71d88a3de3902c7305a55b65947b0b30b866836df36c45bfc50802ae
MD5 hash:
a69ef2d53bf3ac9c71eed0b98d0adb87
SHA1 hash:
8fc540b832a1aa7f57da7269ea2c68f664bc457a
SH256 hash:
9967989c15c0f7ae425e0980837f6caa91bd9475e97c935ff1ca9e00964423e6
MD5 hash:
e80ac907c83884a675b31221c0f9cff0
SHA1 hash:
68830f46c5644e7496d320add7aae88f5ec3f14c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SystemBC

Executable exe 9967989c15c0f7ae425e0980837f6caa91bd9475e97c935ff1ca9e00964423e6

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-09-06 11:47:34 UTC

url : hxxp://85.209.88.29/wevtutil.exe