MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b1f292df0cec2b326d9231003b603d80c5a41c0eebbd51e13ad6d57493a0ec8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b1f292df0cec2b326d9231003b603d80c5a41c0eebbd51e13ad6d57493a0ec8b
SHA3-384 hash: 1ccb99e68d187d7bdf60d52f214710c17a01ab4f626b37bca3010651f59cfe8ccc577596f845480f7572d1e368928827
SHA1 hash: 05d39ea81b735484d13ec1e4b086b6ac539c9b06
MD5 hash: bb8e011a3f18d40849cba38714ea34aa
humanhash: winter-cola-muppet-bluebird
File name:a791759579e3fbed9020da4ec90942ac
Download: download sample
File size:3'264'513 bytes
First seen:2020-11-17 14:49:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ef3fd1c1a81435e51fcc42212e25d2ec (7 x Reconyc)
ssdeep 49152:acbrbwrZu9LrAegRbP77a4usjFu1gMZAP2p+fgbYUEksH+gJYUtuuLZmpYHd:XrbwrowT7o0Fu1W8XEfYKlmpY9
Threatray 79 similar samples on MalwareBazaar
TLSH AFE5E06D227B4883C81B2735A85EDFBB4161BE3C7AA7D275709072AF74613C58B07A34
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
DNS request
Sending a custom TCP request
Creating a file
Moving of the original file
Deleting of the original file
Result
Verdict:
0
Threat name:
Win32.Trojan.Symmi
Status:
Malicious
First seen:
2020-11-17 14:51:35 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Legitimate hosting services abused for malware hosting/C2
Deletes itself
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
b1f292df0cec2b326d9231003b603d80c5a41c0eebbd51e13ad6d57493a0ec8b
MD5 hash:
bb8e011a3f18d40849cba38714ea34aa
SHA1 hash:
05d39ea81b735484d13ec1e4b086b6ac539c9b06
SH256 hash:
8f1a496df33ac0c1725c9a358cad2c684486b694549b80d5bdfc609f871dc352
MD5 hash:
7851cba6cd9c93f44a21cccd3337fffc
SHA1 hash:
22e0d824cd02f5175ed4ea9a6f754a27ae11ec12
SH256 hash:
c3489d73877080e15daed1b14d9c501fcef80a69ce0cd18af4cd7a0d5dbb38fa
MD5 hash:
5829583ffb030486b3651e0bd05412a1
SHA1 hash:
28874fea250e30e694c92b91401c1702bbe02bb4
SH256 hash:
84aafe94cc6585d7f77ffcb413c85b979fb99633b3a6533272da86dec522b50b
MD5 hash:
f3e42c4f9359e8caffad6fbff3991bd5
SHA1 hash:
64983534b957ce30813b00d8db86f9b5d7629d2a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments