🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b583d86c4abc6d6ca57bde802b7e9d8143a249aed6a560a4626e79ae13f6209d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 3


Intelligence 3 IOCs YARA 17 File information Comments

SHA256 hash: b583d86c4abc6d6ca57bde802b7e9d8143a249aed6a560a4626e79ae13f6209d
SHA3-384 hash: b3afe6114c0b012f4503a31de08a54c141cd2e508e85cce2848d483ea5a58a97c3ac2cb0ea7fcf802f525033d8d35c49
SHA1 hash: 10e3b5e5cabcfbe1e79caa1a47efd994122d5429
MD5 hash: a7900cdbb2912d76aa6329c5c41d8609
humanhash: lake-sixteen-pluto-march
File name:MlсrоsоftЕdgеSеtup.appx
Download: download sample
Signature RaccoonStealer
File size:24'637'335 bytes
First seen:2023-09-30 14:56:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:kKc5VmYor9Dcm9n7EaLY9eoRbFQ067wNg8W75dBGNUNpWXNM0AsfjYgsErOwm9r1:kKc5MYa939oZBk/XBGWNc+0AwjNs33h1
TLSH T13A4733D93063B115FAC90C20E92A18D2B5579FA5F5042C7124F6AC88BFE3DDAE1CE275
TrID 67.0% (.MSIX) MSIX Windows app package (26500/1/3)
20.2% (.FB2K-COMPONENT) foobar2000 component (8000/1/2)
10.1% (.ZIP) ZIP compressed archive (4000/1)
2.5% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter crep1x
Tags:ClearFake HIjackLoader Raccoon RaccoonStealer signed zip

Code Signing Certificate

Organisation:STECH CONSULTANCY LIMITED
Issuer:SSL.com Code Signing Intermediate CA RSA R1
Algorithm:sha256WithRSAEncryption
Valid from:2023-04-03T01:35:11Z
Valid to:2024-04-01T01:35:11Z
Serial number: 0ad3ec95833032eebf53b660984cc67d
Intelligence: 8 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 7f7c9adfc6447b9a1a6da4c60bde9d6ed74482d530534c7599651d1de55fef97
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
192
Origin country :
FR FR
File Archive Information

This file archive contains 20 file(s), sorted by their relevance:

File name:MicrosoftEdgeSetup.exe
File size:1'600'888 bytes
SHA256 hash: 7d94e045fc80fb985385702b11312b6dbadecf802168328cb0db0f62cc66fa3c
MD5 hash: 58d8d75b0ca5e316862ed81cdb2d0c67
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:AppxManifest.xml
File size:2'167 bytes
SHA256 hash: 199437a94fd30b5cb3b0a4f5c05332580e574497b06328f22dcbeb8753042645
MD5 hash: 9533eb513364512341ce494ace68af5a
MIME type:text/xml
Signature RaccoonStealer
File name:MicrosoftEdgeSetup.exeSquare150x150Logo.scale-100.png
File size:532 bytes
SHA256 hash: f3f304b7b13a445b18a2d69308c488df29af13b2f729d64626f8fd225ab67b4c
MD5 hash: a9f0d833d29a9195e6d5dc539a4dca3b
MIME type:image/png
Signature RaccoonStealer
File name:[Content_Types].xml
File size:1'015 bytes
SHA256 hash: d93532c87bfa9573670490cbfc46d894ea5e161a1ec2dd77f21def41c15f958f
MD5 hash: 1deb302a105714c93f96622274c8c6d7
MIME type:text/xml
Signature RaccoonStealer
File name:AppxSignature.p7x
File size:10'536 bytes
SHA256 hash: 16e21617f24a6e9d99e0ffbd38e4f077b6c8004701d69c0ca60251d8109fc1f4
MD5 hash: b7a33c3119cf0f71635a092aa6d1c883
MIME type:application/octet-stream
Signature RaccoonStealer
File name:PsfRuntime32.dll
File size:346'736 bytes
SHA256 hash: 4fdcf20237f161fb827bccd1faaee61217e5f8d3229a8dff507c98d1bda9aac6
MD5 hash: 4effa3c11daf79a3a76de4db923f36bb
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:Store50x50Logo.scale-100.png
File size:197'996 bytes
SHA256 hash: 3b28d13df24bc8649ea3f220503b9743687f4fd80b74977b46d68010b86c9e0f
MD5 hash: e5e74e7c426232aea1792a5381e6904c
MIME type:image/png
Signature RaccoonStealer
File name:StartingScriptWrapper.ps1
File size:13'462 bytes
SHA256 hash: c67b8cc2af757b3ac17908bb6a4401f647d85c1fe52bcdecaff4f613d3837270
MD5 hash: e06d0ab3e6cb84e09450eba6815adebd
MIME type:text/plain
Signature RaccoonStealer
File name:config.json
File size:372 bytes
SHA256 hash: f5a0191c8622041d31ecfa05f90718b74034b8645a37ee41e7570769e138bda6
MD5 hash: 2531b19c56307861918ee932034aab4b
MIME type:text/plain
Signature RaccoonStealer
File name:AiStubX64.exe
File size:605'296 bytes
SHA256 hash: 815d2e32e948681c85d56aff9eb9ac597647effa8da6db2b81fa2109f9875ff6
MD5 hash: e89f448e8f41a590c51d34948bdc9c1e
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:PsfRuntime64.dll
File size:429'168 bytes
SHA256 hash: 8b86893d2a721474b816bfc0228dbbe9b9bc6c1d7bde870c37200074501081fb
MD5 hash: 2a0cc46fccb40482c57893459d1154d5
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:Registry.dat
File size:8'192 bytes
SHA256 hash: 32293d5425d1701f30696a2b89acd061f1d0ef2a932a1ef2ae764f5881b3f46c
MD5 hash: 7b6d4f8c326787810b8d86a2ea16b6d0
MIME type:application/octet-stream
Signature RaccoonStealer
File name:AppxBlockMap.xml
File size:32'040 bytes
SHA256 hash: 6ccc1675275a09f2396c3c996d0eaebeb2c6cdc6254f46016f6d5b074093b9d6
MD5 hash: 2955463f96ebbd89def896ac15fcbc1a
MIME type:text/xml
Signature RaccoonStealer
File name:resources.pri
File size:1'280 bytes
SHA256 hash: a36a2592fc72b5bb3668ac350ca9a7d8a12a9879ebd814c40c5fd8bc9a54c19d
MD5 hash: 18b9c2abba208ea79349a7746831a208
MIME type:application/octet-stream
Signature RaccoonStealer
File name:PsfRunDll32.exe
File size:90'736 bytes
SHA256 hash: 1455ce13c83c8e542770662991f46926c629c782f985fcbbf7267526e7b48f64
MD5 hash: e403f7e28f45b01681b8c49f63711e9d
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:CodeIntegrity.cat
File size:11'764 bytes
SHA256 hash: 1e98a658b294ec716ce7fa471f2892775f69711749fa156544491a0917708699
MD5 hash: a158915e4612de6e41252abc407d6afd
MIME type:application/octet-stream
Signature RaccoonStealer
File name:MicrosoftEdgeSetup.exeSquare44x44Logo.scale-100.png
File size:1'289 bytes
SHA256 hash: a680d90930487bfef541422718a30e77fa038d1a11434304354a9fb8769e78a5
MD5 hash: f41a624d6b0de8f13688b7c539e862a2
MIME type:image/png
Signature RaccoonStealer
File name:chrome.ps1
File size:663 bytes
SHA256 hash: ce54b949607227a4b5b1f521b5ec0c37e4bde1549c667e53f56cf3b5b6156d35
MD5 hash: bfe16fc5d100757bd9dec4ef1aa42913
MIME type:text/plain
Signature RaccoonStealer
File name:PsfRunDll64.exe
File size:109'680 bytes
SHA256 hash: 5858841270d5b2f859fb69bb2e51f582f8e4c0e5a98e8f34a34bf30f0f1c5066
MD5 hash: c82fc53a6666c0d92f1a82931f72565e
MIME type:application/x-dosexec
Signature RaccoonStealer
File name:KSPSService.exe
File size:23'151'176 bytes
SHA256 hash: d60d4da2cfe120138a3fde66694b40ae2710cfc2af33cb7810b3a0e9b1663a4f
MD5 hash: d113b3debc7e0a2da4369dd8d1dbad53
MIME type:application/x-dosexec
Signature RaccoonStealer
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug greyware masquerade packed
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware discovery evasion persistence spyware stealer trojan
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
System policy modification
Enumerates physical storage devices
Drops file in Program Files directory
Checks system information in the registry
Checks installed software on the system
Checks whether UAC is enabled
Installs/modifies Browser Helper Object
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Registers COM server for autorun
Blocklisted process makes network request
Downloads MZ/PE file
Modifies Installed Components in the registry
Sets file execution options in registry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:msix_file
Author:Stuart Gonzalez
Description:Detection for .msix files
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RaccoonStealer

zip b583d86c4abc6d6ca57bde802b7e9d8143a249aed6a560a4626e79ae13f6209d

(this sample)

  
Delivery method
Distributed via web download

Comments