MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a91d59c97ca82cdb4fc003a58f71e96d9006fd9de285b8b4b9292c334509e364. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a91d59c97ca82cdb4fc003a58f71e96d9006fd9de285b8b4b9292c334509e364
SHA3-384 hash: 104b75cc05a9e6d25a34ae786076923de6e3a9335dfa8f23f4b19863ca153857d0da65551d7c986f6ce0b33f5377b669
SHA1 hash: 77058def74b976d7015784e203248d055e4628f6
MD5 hash: a01b172cd722187497d58a446ef1fe6d
humanhash: april-georgia-nitrogen-fillet
File name:a01b172cd722187497d58a446ef1fe6d
Download: download sample
File size:192'513 bytes
First seen:2020-11-17 12:25:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b71ae52e8715ee7bfaa0c9df227db54a
ssdeep 3072:QKvgQQOhn9xKTXLFMphlflrR+XWGGxKQrCLFpMVg09TvZU:Q8QOlKmp3flCJQWLFpMVgaU
Threatray 32 similar samples on MalwareBazaar
TLSH 2014B003FB744DA5F9FAB13BB4E7CBC6CE50D9163A639225D06DE78A5F05E06A203244
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
Creating a window
Moving of the original file
Deleting of the original file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-07 09:20:00 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: RenamesItself
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Program crash
Deletes itself
Loads dropped DLL
Executes dropped EXE
ServiceHost packer
Unpacked files
SH256 hash:
a91d59c97ca82cdb4fc003a58f71e96d9006fd9de285b8b4b9292c334509e364
MD5 hash:
a01b172cd722187497d58a446ef1fe6d
SHA1 hash:
77058def74b976d7015784e203248d055e4628f6
SH256 hash:
0a576ad7700143ab855349d24da86e4c01c5870b563a5cf68197c3d9669a5f29
MD5 hash:
6f87b978aa5f89fda04105bdeb46bd0a
SHA1 hash:
c9d4be4c8063a72435040b5c89f27a341c5c6e83
SH256 hash:
c68e4f77d69d24254a6ba6a307a65364013c0f8c177f2b1206984571c40f4f9a
MD5 hash:
060c5f09ae0597e2745924f8eb23311d
SHA1 hash:
1e2de8712c2ced5a69405a95b4a895c9c9e7c967
SH256 hash:
dddac9cacfc78e1652b0010c4806f22d16e5abc867e3c8dc5463dadff2881792
MD5 hash:
80ead838038a6cb8a90ed1ed4ff30d46
SHA1 hash:
c6b67f2c8ee19b6d8d274c3f3347b35fdf42a3b7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments