MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac1b332e6958c5b81be1b747c8a30172741514ed397952e01ad174be94f112a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: ac1b332e6958c5b81be1b747c8a30172741514ed397952e01ad174be94f112a4
SHA3-384 hash: 9f2bcd5c218151c66299fac8b80b079708a0601a076e86dee0febb577169221b6338d34206266dd28132180779f49f70
SHA1 hash: 3bb0d5fdb3a6e0d268f387a6ef5ec3e22e962d80
MD5 hash: 79af776b8153ff8aeb1e9fdd343f02d3
humanhash: undress-batman-jig-spring
File name:ac1b332e6958c5b81be1b747c8a30172741514ed397952e01ad174be94f112a4
Download: download sample
File size:4'417'751 bytes
First seen:2020-06-03 09:18:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dbbc718f7f0ca351f7a0e645fde2dbea
ssdeep 98304:3+I3L/wlG4UZej0jvy5SbWf+YFCbJBAUZLs2K5:3HPvyQaf+HbJVDK5
Threatray 58 similar samples on MalwareBazaar
TLSH 2916D103F2818472D81719700C77673A6A36FF116F258A93B794FE6D1D732E2973628A
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vmpbad
Status:
Malicious
First seen:
2020-06-03 17:39:17 UTC
AV detection:
44 of 48 (91.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious behavior: RenamesItself
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments