MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b365190897188c3b97b140e53aa8ab1564bf1cdc9484ec52ad022b97247075f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 10


Intelligence 10 IOCs 1 YARA File information Comments 1

SHA256 hash: b365190897188c3b97b140e53aa8ab1564bf1cdc9484ec52ad022b97247075f9
SHA3-384 hash: 4546b9086412a622b48356b87f48b9f810dec53bbd209a370c5a49a3585f4860b909b1ef685aad57053943ef8b15772f
SHA1 hash: cf036a42b6a2fb6455385efe97ff106ed749bf71
MD5 hash: a5ad647c4412eb01782294dd17a2c404
humanhash: zulu-pip-quebec-snake
File name:a5ad647c4412eb01782294dd17a2c404
Download: download sample
Signature DanaBot
File size:2'237'440 bytes
First seen:2022-03-22 19:08:04 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e36bf2cd7229c855562e0cd74016f1d8 (6 x DanaBot)
ssdeep 24576:wA66bMGUv6xWvR3bdZl+D0IhmNOaS+jeR2Xzo2H01LkFvqPJVoXKm9M+MxpUULRv:wrfp3bx+ySbRAzo2U1iqRMzzT8h
TLSH T195A54B31A344B12BD4BD173A4166A25D807A2239D9119C7BF7D04E4CBFBDF90AA2D70B
Reporter zbetcheckin
Tags:32 DanaBot exe

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
23.254.134.53:443 https://threatfox.abuse.ch/ioc/439889/

Intelligence


File Origin
# of uploads :
1
# of downloads :
554
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Launching a process
Sending a custom TCP request
Sending an HTTP GET request
Creating a file in the %temp% directory
Сreating synchronization primitives
Searching for synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm cmstp.exe comsvcs.dll csc.exe danabot dfshim.dll evasive expand.exe fingerprint forfiles.exe mmc.exe mpcmdrun.exe msbuild.exe odbcconf.exe pcwutl.dll pnputil.exe print.exe rasautou.exe regini.exe regsvr32.exe replace.exe setupapi.dll stealer upatre url.dll vbc.exe verclsid.exe xwizard.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Midie
Status:
Malicious
First seen:
2022-03-22 19:09:13 UTC
File Type:
PE (Exe)
AV detection:
18 of 42 (42.86%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cloudeye
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Suspicious use of SetThreadContext
Blocklisted process makes network request
Unpacked files
SH256 hash:
b365190897188c3b97b140e53aa8ab1564bf1cdc9484ec52ad022b97247075f9
MD5 hash:
a5ad647c4412eb01782294dd17a2c404
SHA1 hash:
cf036a42b6a2fb6455385efe97ff106ed749bf71
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe b365190897188c3b97b140e53aa8ab1564bf1cdc9484ec52ad022b97247075f9

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-03-22 19:08:10 UTC

url : hxxp://185.173.34.66/float.exe