🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab0413fb159602aeaee3b761c822bb179c9c949f780b2c5f7bb5cdb978ed0bd4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: ab0413fb159602aeaee3b761c822bb179c9c949f780b2c5f7bb5cdb978ed0bd4
SHA3-384 hash: 42d21ecee27a04a768445ff0042a95d9a27b4ccf6f900d9ec5ba1edca27d8816342a80ccb429cd1cd3c9e62b902d727f
SHA1 hash: d2969a286adb832b074b5bf3378d0a082a29ef29
MD5 hash: b42d99e223db12e20b424d56fa27017a
humanhash: item-texas-asparagus-virginia
File name:SecuriteInfo.com.Gen.Variant.Barys.434263.28497.26812
Download: download sample
File size:1'871'872 bytes
First seen:2023-06-13 04:28:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 607393dbbe7cc21d390c7b51ff7bd7c3
ssdeep 49152:2vrs3D6TUdgBzeJYebqE4qchWry2hnKv+:Q+OBSbqE5kWrBn8+
Threatray 2 similar samples on MalwareBazaar
TLSH T11F85336F424A5DFAF92F373CFE05C5353406F4E9E2D30B279BA858C60B5B882148966D
TrID 81.7% (.EXE) UPX compressed Win32 Executable (27066/9/6)
6.1% (.EXE) OS/2 Executable (generic) (2029/13)
6.0% (.EXE) Generic Win/DOS Executable (2002/3)
6.0% (.EXE) DOS Executable Generic (2000/1)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
313
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Gen.Variant.Barys.434263.28497.26812
Verdict:
Malicious activity
Analysis date:
2023-06-13 04:30:40 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Creating a window
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
60%
Tags:
greyware lolbin packed shell32.dll
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 886374 Sample: SecuriteInfo.com.Gen.Varian... Startdate: 13/06/2023 Architecture: WINDOWS Score: 48 24 Multi AV Scanner detection for submitted file 2->24 8 loaddll64.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 8 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 9 12->20         started        process6 22 WerFault.exe 21 9 18->22         started       
Threat name:
Win64.Trojan.Barys
Status:
Malicious
First seen:
2023-06-13 04:29:06 UTC
File Type:
PE+ (Dll)
Extracted files:
69
AV detection:
8 of 37 (21.62%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
upx
Behaviour
Suspicious use of WriteProcessMemory
Program crash
UPX packed file
Unpacked files
SH256 hash:
ab0413fb159602aeaee3b761c822bb179c9c949f780b2c5f7bb5cdb978ed0bd4
MD5 hash:
b42d99e223db12e20b424d56fa27017a
SHA1 hash:
d2969a286adb832b074b5bf3378d0a082a29ef29
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments