MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bd4bb54603325514f1bd9004b7a946f613794046756da7b7534541f36b55ef5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9bd4bb54603325514f1bd9004b7a946f613794046756da7b7534541f36b55ef5
SHA3-384 hash: be7802015a634a8acc8408e9a71488b98fd3057cd59e24141d3903e16a1cdf4475e16f85d1cc9c953bbc70da7aa6b4e2
SHA1 hash: b737c355cd1378135c2dbea049c6135a163eaef5
MD5 hash: 00c65f1d3c5b1d3bfb5241ce41dc2d76
humanhash: may-five-green-carpet
File name:af9e817a5c8aca568d6d355c56bdac6e
Download: download sample
File size:27'136 bytes
First seen:2020-11-17 14:45:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 87bed5a7cba00c7e1f4015f1bdae2183 (3'034 x Jadtre, 23 x IcedID, 17 x Blackmoon)
ssdeep 768:Od5u7mNGtyVfj/5sQGPL4vzZq2oZ7GUxtKy:Od5z/fjRvGCq2w7L
Threatray 1'289 similar samples on MalwareBazaar
TLSH C5C2D072CE80C4FFC0CB3072204522CB9B575672957A6867A750981E7DBCDD0EA7A753
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a window
Changing an executable file
DNS request
Connection attempt
Sending an HTTP POST request
Modifying an executable file
Creating a file
Running batch commands
Creating a process with a hidden window
Connection attempt to an infection source
Infecting executable files
Threat name:
Win32.Virus.Wapomi
Status:
Malicious
First seen:
2020-11-17 14:46:43 UTC
AV detection:
26 of 28 (92.86%)
Threat level:
  5/5
Unpacked files
SH256 hash:
9bd4bb54603325514f1bd9004b7a946f613794046756da7b7534541f36b55ef5
MD5 hash:
00c65f1d3c5b1d3bfb5241ce41dc2d76
SHA1 hash:
b737c355cd1378135c2dbea049c6135a163eaef5
SH256 hash:
9d6972ec9e83e47d7e608f076a77deb06da55d54456656c6b4dbb14c8ca3603d
MD5 hash:
252e37b81fa894b1ddacff78dc7009ff
SHA1 hash:
e9084b6227830b2564995a39e783c30df7a0d531
Detections:
win_unidentified_045_g0 win_unidentified_045_auto
SH256 hash:
22044edfd161b15c0adb7acd0040f0ca55660a06ee1a0f160ec9304061c64fe1
MD5 hash:
a7840613b401fec31ef770b15c096d4c
SHA1 hash:
e1c74b6f56393b821d8a7f30c5134db95da580ec
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments