MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6a7ca22f65e49860d0df88cdad557dc84250fbe3066ba9a8db986f46d4b0f9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Emotet (aka Heodo)


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: a6a7ca22f65e49860d0df88cdad557dc84250fbe3066ba9a8db986f46d4b0f9b
SHA3-384 hash: d3e252013a4efb7fbb1fff3a8ed2733c58d184981099083212cf8f2365d9ab954f55dbe7c8d39cdcb470002da0180c6c
SHA1 hash: c78ced8c22a8dd0c7a8f9d2252f52fc63b02b1f2
MD5 hash: ad42b1618f0ca5b7ad52a7eb524bb732
humanhash: missouri-virginia-iowa-white
File name:a6a7ca22f65e49860d0df88cdad557dc84250fbe3066ba9a8db986f46d4b0f9b
Download: download sample
Signature Heodo
File size:245'760 bytes
First seen:2020-03-23 18:53:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 92223695e0973422fbfe72b22258bd52 (1 x Heodo)
ssdeep 3072:+DhazfEqKsqls8jTxzNbcXMS0VlGkBpp/mBb4lCm6Kt:QhqfEqKs/8pZDSHkBLS8km6K
Threatray 25 similar samples on MalwareBazaar
TLSH 2034F7CF547CC545E946A1B904B90D38892ECD2B1C969BBBED80237DF6DAE24D05BF80
Reporter Marco_Ramilli
Tags:Emotet exe Heodo

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Emotet
Author:JPCERT/CC Incident Response Group
Description:detect Emotet in memory
Reference:internal research
Rule name:win_emotet_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Heodo

Executable exe a6a7ca22f65e49860d0df88cdad557dc84250fbe3066ba9a8db986f46d4b0f9b

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
MULTIMEDIA_APICan Play MultimediaMSACM32.dll::acmDriverRemove
MSACM32.dll::acmStreamSize
WINMM.dll::mixerGetDevCapsW
RPC_APICan Execute Remote ProceduresRPCRT4.dll::RpcMgmtEnableIdleCleanup
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AddAce
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::AttachConsole
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryExW
WIN_CRYPT_APIUses Windows Crypt APICRYPT32.dll::CertEnumCRLsInStore
WIN_TIME_APICan Modify TimeKERNEL32.dll::SetSystemTimeAdjustment
WIN_USER_APIPerforms GUI ActionsUSER32.dll::BroadcastSystemMessageA

Comments