🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99ec51581852b3e031c63c9c0f5138eaf86406a2e70e9d8dfe3ac540d19ef8ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



YellowCockatoo


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 99ec51581852b3e031c63c9c0f5138eaf86406a2e70e9d8dfe3ac540d19ef8ff
SHA3-384 hash: c492e05e3baf117670774230411b7ea88c80ab8d719566b2c175401043b2d6668ebb7d13d1fe5aff73da35a367dbef17
SHA1 hash: 092591a8caeaa36aa59a3f110a8217a86ab3f7ff
MD5 hash: cf7a6433c85265b8dea9b349cf8f477d
humanhash: ink-tennessee-september-arkansas
File name:installer-package.exe.zip
Download: download sample
Signature YellowCockatoo
File size:3'279'178 bytes
First seen:2023-09-06 17:28:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:VO8ahg/po/uqaTS9ajn1dHcybEFXfm5L6S4:VOR+oZaTwajnALPuL6S4
TLSH T119E5DDDED1A76CA65E2B9711C5BB80E5C543B027FBB3D2A4D5F263802212721C7BC49B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter SquiblydooBlog
Tags:file-pumped Jupyter Polazert solarmarker YellowCockatoo zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
130
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:installer-package.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:314'699'384 bytes
SHA256 hash: e38b838995dfe3df7419264d3a02877fe8239e691b2bcd18b843afe8c7f9961e
MD5 hash: 8f76d45f090362e4fd52e3eb7d5db647
De-pumped file size:314'688'000 bytes (Vs. original size of 314'699'384 bytes)
De-pumped SHA256 hash: cc67e458493aceaa050a63d8da7588a8edc638b06fa646d762f2a67e06783487
De-pumped MD5 hash: 1677cf3170e6ecf9d446467fa32c2f6e
MIME type:application/x-dosexec
Signature YellowCockatoo
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
large-file overlay packed
Threat name:
Binary.Trojan.Hulk
Status:
Malicious
First seen:
2023-09-06 17:29:05 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments