MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99a1c6ce53b04d93ac128e005fa88751b9920038e3c1b0e800c1c21fe2871427. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 99a1c6ce53b04d93ac128e005fa88751b9920038e3c1b0e800c1c21fe2871427
SHA3-384 hash: b0bc251d51542fe292736a6a7f713ac1c7fc4a8bf5959c5b09e14544d5ffcdd6113b1f97b9e55ab4669ae99b4953eb0a
SHA1 hash: b2e4b89bbc95ca0b1ce76b5835e4e9d670a46964
MD5 hash: f2b21d0a8c831d1ca77c69f05e16ad55
humanhash: august-bakerloo-jersey-florida
File name:saintserver
Download: download sample
Signature n/a
File size:295'596 bytes
First seen:2022-08-05 07:00:39 UTC
Last seen:Never
File type:unknown
MIME type:text/plain
ssdeep 3072:vGNgjS+Z69ns0mKP9WLvgcmykua+k+c1meaUhrmECvqma/4ApLkfq7dIWYWkhhXW:vGNgpA9npcLdhkk+lmE7kfiLkbxPE
TLSH T1A0545B3623427D9973AB1F89F90139620CEA74E7A3E2942DF7C01A9A106B464ED0DD76
Reporter @JAMESWT_MHT
Tags:208-67-105-125

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
IT IT
Mail intelligence
No data
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
hacktool obfuscated
Result
Verdict:
MALICIOUS
Details
Base64 Encoded URL
Detected an ANSI or UNICODE http:// or https:// base64 encoded URL prefix.
Threat name:
ByteCode-MSIL.Infostealer.DarkStealer
Status:
Malicious
First seen:
2022-08-02 09:46:09 UTC
File Type:
Text
AV detection:
13 of 25 (52.00%)
Threat level:
  5/5

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

unknown 99a1c6ce53b04d93ac128e005fa88751b9920038e3c1b0e800c1c21fe2871427

(this sample)

  
Delivery method
Distributed via web download

Comments