MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a57337366ce7dc7b059633a944b048c25457841f2916573062973003793a0b0c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a57337366ce7dc7b059633a944b048c25457841f2916573062973003793a0b0c
SHA3-384 hash: 86cb8c64a0eba1af5123f50eb76bb4b0b19e4b896ec2e3761757fd015110046a989e8e0a88bfa05829dd59eb234cb054
SHA1 hash: ef7a4af9d4b9f5c3756f4d2bdf2efc25bab90058
MD5 hash: 76116a196f68c32d61872d0d97568072
humanhash: xray-lemon-saturn-mango
File name:SecuriteInfo.com.Generik.NISXSHK.25544
Download: download sample
File size:176'128 bytes
First seen:2020-03-28 11:00:33 UTC
Last seen:2020-05-06 17:16:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 8cb34ed4f039025b09b2673e40a57c75
ssdeep 3072:aHmev47bJV+JDX3up3UlkvXrbW+p7iWUMiSjS6Zj2iEB:jBbJV+NXep3UK/rnphUMi76ZO
Threatray 15 similar samples on MalwareBazaar
TLSH 6004291BB3A308FEC657D17486E7E732A472F0141324BE2E1794DF332E65C245B6A968
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
2
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe a57337366ce7dc7b059633a944b048c25457841f2916573062973003793a0b0c

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WININET.dll::InternetCloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA

Comments