MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b33b3beb75ffe4fda66b9b38e3121f1abb4b7896f99ba4f35b511c7ed63c305c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TA505


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b33b3beb75ffe4fda66b9b38e3121f1abb4b7896f99ba4f35b511c7ed63c305c
SHA3-384 hash: 4542ac5230b941b9e6575b7c8b06e1a437347f2d8d9cd49cc22d0cb709c0d9afc816de09510dc9b6915283f7561f6d8f
SHA1 hash: d9dc1f8a66fb37aae209721177a1746155f389f1
MD5 hash: 861f423251bfa7c707cd76b2cd4225a0
humanhash: snake-nevada-comet-video
File name:rgoc1.bin
Download: download sample
Signature TA505
File size:379'904 bytes
First seen:2020-09-09 14:01:45 UTC
Last seen:2020-09-09 14:45:13 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 6c57c65bc024dbc1f104b57b3bdf3ff0 (1 x TA505)
ssdeep 6144:cWrTLFgK99HT40EcTMAfD3LGMRxXqy31y069YRioKv6u5Is7K0:cWrSK9xGcTMAu2fPRbKL5Is
Threatray 4 similar samples on MalwareBazaar
TLSH 7784E023FED2D1B4D4D740359C64496D03FF8A33BB9868B79B401AD9AC65AD11BAF320
Reporter JAMESWT_WT
Tags:32bit dll TA505

Intelligence


File Origin
# of uploads :
2
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.GraceWire
Status:
Malicious
First seen:
2020-09-09 14:03:08 UTC
File Type:
PE (Dll)
Extracted files:
2
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Blacklisted process makes network request
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments