MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4d7844280a7af693b468225e73496e2341faac96db6bc5194e58e22e2bf3413. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Meterpreter


Vendor detections: 11


Intelligence 11 IOCs YARA 4 File information Comments 1

SHA256 hash: a4d7844280a7af693b468225e73496e2341faac96db6bc5194e58e22e2bf3413
SHA3-384 hash: 48cd90d7597c4b6ea2eabc936f832f085462cc0f4a8317796f7d8a47891f63ed7c05a85c0e2f5723c8a3a3643ad4cdf2
SHA1 hash: 502bcace354b9b97c86cd35bbd9854c28806a66b
MD5 hash: 7fb454cdb631c748ad5a0d0847b24fb1
humanhash: glucose-louisiana-low-oregon
File name:WinSearch.exe
Download: download sample
Signature Meterpreter
File size:54'111 bytes
First seen:2023-06-15 11:17:51 UTC
Last seen:2023-06-15 12:05:51 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash a839a3a88d63510bcb7e2dcdddf17765 (1 x RedLineStealer, 1 x Meterpreter)
ssdeep 768:MKL0B0KsXszANnpT6Effz+Skktl4PP3lLuzZPKqGY1x0LBP3p4d:fz+S9l4PP3lLuBZGY1G9P3p4d
Threatray 90 similar samples on MalwareBazaar
TLSH T11433E9DCFEE4ECE6D982933E82E7C3B5563CE95049631F97B720BA355A033905398146
TrID 32.2% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
20.5% (.EXE) Win64 Executable (generic) (10523/12/4)
12.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
9.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter JAMESWT_WT
Tags:exe Meterpreter WhisperGate

Intelligence


File Origin
# of uploads :
2
# of downloads :
386
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
WinSearch.exe
Verdict:
Malicious activity
Analysis date:
2023-06-15 11:19:24 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Searching for the window
Running batch commands
Creating a process with a hidden window
Launching a process
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Launching cmd.exe command interpreter
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
CheckCmdLine
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug overlay spyeye
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus detection for URL or domain
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 888273 Sample: WinSearch.exe Startdate: 15/06/2023 Architecture: WINDOWS Score: 76 24 golden-starship-baec18.netlify.app 2->24 28 Multi AV Scanner detection for domain / URL 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Antivirus detection for URL or domain 2->32 34 Multi AV Scanner detection for submitted file 2->34 8 WinSearch.exe 2->8         started        signatures3 process4 signatures5 36 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 8->36 11 cmd.exe 1 8->11         started        13 cmd.exe 1 8->13         started        process6 process7 15 powershell.exe 15 15 11->15         started        18 conhost.exe 11->18         started        20 powershell.exe 11 13->20         started        22 conhost.exe 13->22         started        dnsIp8 26 golden-starship-baec18.netlify.app 34.159.132.250, 443, 49692 ATGS-MMD-ASUS United States 15->26
Threat name:
Win32.Downloader.Malgent
Status:
Malicious
First seen:
2023-06-14 19:04:39 UTC
File Type:
PE (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Blocklisted process makes network request
Unpacked files
SH256 hash:
a4d7844280a7af693b468225e73496e2341faac96db6bc5194e58e22e2bf3413
MD5 hash:
7fb454cdb631c748ad5a0d0847b24fb1
SHA1 hash:
502bcace354b9b97c86cd35bbd9854c28806a66b
Detections:
win_whispergate_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:Windows_Trojan_Metasploit_38b8ceec
Author:Elastic Security
Description:Identifies the API address lookup function used by metasploit. Also used by other tools (like beacon).
Rule name:Windows_Trojan_Metasploit_38b8ceec
Description:Identifies the API address lookup function used by metasploit. Also used by other tools (like beacon).
Rule name:win_whispergate_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.whispergate.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2023-06-15 13:21:19 UTC

this exe is dropped from sample `b621c0e744c03b45c0b32f244a6b8b4a84c449ffde4a62e52d8acfdf6fac264a`