MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba57f8fcb28b7d1085e2e5e24bf2a463f0fa4bbbeb3f634e5a122d0b8dbb53cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ba57f8fcb28b7d1085e2e5e24bf2a463f0fa4bbbeb3f634e5a122d0b8dbb53cc
SHA3-384 hash: a9aa8b32d708257e1e0933232e893f77daf7b846c266d7a70293eea9781ed15dae212903fe17c107d0af4aabc6d85ead
SHA1 hash: 5f8d04df7a7c63b4bee2ba5f6ac3fa833c7f1872
MD5 hash: 8ee9956a0631c641470a94fdc7b44430
humanhash: rugby-california-alaska-sink
File name:ba57f8fcb28b7d1085e2e5e24bf2a463f0fa4bbbeb3f634e5a122d0b8dbb53cc
Download: download sample
File size:115'832 bytes
First seen:2021-01-26 13:00:14 UTC
Last seen:2021-01-26 14:34:03 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e59a872503ad35533b2cba3d88f7f028
ssdeep 3072:ZNESzVz7TEG4SDu3ZKi3PS+rkpYZiyPU2:FRTEG42u3Ii3PJWYR7
TLSH 05B36D4637A500BAE5679278CDE39A57E7B2B451473083CF037446EA2F137D1AE3A322
Reporter JAMESWT_WT
Tags:2 TOY GUYS LLC

Code Signing Certificate

Organisation:Symantec Time Stamping Services CA - G2
Issuer:Thawte Timestamping CA
Algorithm:sha1WithRSAEncryption
Valid from:Dec 21 00:00:00 2012 GMT
Valid to:Dec 30 23:59:59 2020 GMT
Serial number: 7E93EBFB7CC64E59EA4B9A77D406FC3B
Intelligence: 85 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 0625FEE1A80D7B897A9712249C2F55FF391D6661DBD8B87F9BE6F252D88CED95
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
136
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ba57f8fcb28b7d1085e2e5e24bf2a463f0fa4bbbeb3f634e5a122d0b8dbb53cc
Verdict:
No threats detected
Analysis date:
2021-01-26 13:07:07 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Contains functionality to detect sleep reduction / modifications
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.NukeSped
Status:
Malicious
First seen:
2020-11-11 10:45:00 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Modifies system certificate store
Blocklisted process makes network request
Unpacked files
SH256 hash:
ba57f8fcb28b7d1085e2e5e24bf2a463f0fa4bbbeb3f634e5a122d0b8dbb53cc
MD5 hash:
8ee9956a0631c641470a94fdc7b44430
SHA1 hash:
5f8d04df7a7c63b4bee2ba5f6ac3fa833c7f1872
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments