🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 af49eebde405cbfeb5003747f48622d2c1292a3eba28b52eaba68532a63d1e02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: af49eebde405cbfeb5003747f48622d2c1292a3eba28b52eaba68532a63d1e02
SHA3-384 hash: e8cdc6e0f94ebb4f0b50e0c55ec1c693dd8fee08f83b9ebc7a32baa8e45939d485c9f16d44c802ed2327c0437d40dc75
SHA1 hash: fe12fdc873979ec050eb8c2d1e697e2f78dcd17f
MD5 hash: 11d433204dd28ee2d275411b70b0c746
humanhash: idaho-five-william-eleven
File name:af49eebde405cbfeb5003747f48622d2c1292a3eba28b52eaba68532a63d1e02
Download: download sample
File size:25'242'121 bytes
First seen:2023-05-14 09:17:45 UTC
Last seen:2023-09-16 14:34:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash fdce173ae7d96c9a7c9c46455070f0b0
ssdeep 786432:cxuvcKZwiBF2CBwtj9ttcjzx8xN1RQE5LD4Gp5iTz2oC4inkGt7ZJevVOYPSp8pu:cxuvcKZwiBF2CBwtj9ttcjzx8xN1RQEB
Threatray 3 similar samples on MalwareBazaar
TLSH T130470A27F2908F35C0EE573F819F86409372545A0BA3A7C702D8A679FE8E2E10D7575A
TrID 53.8% (.EXE) Win64 Executable (generic) (10523/12/4)
15.3% (.MZP) WinArchiver Mountable compressed Archive (3000/1)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.2% (.EXE) Generic Win/DOS Executable (2002/3)
10.2% (.EXE) DOS Executable Generic (2000/1)
File icon (PE):PE icon
dhash icon 0000000000000000 (907 x AgentTesla, 573 x Formbook, 316 x RedLineStealer)
Reporter petikvx

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
deducao_hzfv.vbs
Verdict:
Malicious activity
Analysis date:
2023-05-12 09:57:06 UTC
Tags:
loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
DNS request
Sending an HTTP GET request
Creating a file
Creating a process from a recently created file
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
MalwareBazaar
LanguageCheck
CheckNumberOfProcessor
CheckCmdLine
Verdict:
Malicious
Threat level:
  10/10
Confidence:
91%
Tags:
greyware keylogger keylogger
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
25 / 100
Signature
May use the Tor software to hide its network traffic
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 865680 Sample: ohKI6WlK0M.exe Startdate: 14/05/2023 Architecture: WINDOWS Score: 25 22 May use the Tor software to hide its network traffic 2->22 6 ohKI6WlK0M.exe 16 2->6         started        10 texthost.exe 2->10         started        12 texthost.exe 2->12         started        process3 dnsIp4 20 s3.timeweb.com 92.53.116.138, 49695, 80 TIMEWEB-ASRU Russian Federation 6->20 16 C:\multuser\texthost.exe, PE32+ 6->16 dropped 18 C:\Users\user\AppData\...\ClimaxSFX[1].mp4, PE32+ 6->18 dropped 14 texthost.exe 1 6->14         started        file5 process6
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
persistence
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments