🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba8f9e7afe5f78494c111971c39a89111ef9262bf23e8a764c6f65c818837a44. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 13


Intelligence 13 IOCs YARA 7 File information Comments

SHA256 hash: ba8f9e7afe5f78494c111971c39a89111ef9262bf23e8a764c6f65c818837a44
SHA3-384 hash: c36ea5b2233645f75647a0984285c6a03f33e8744847958ee8a38616f05a08897df1085a091cfa34f3b56f9d6150f417
SHA1 hash: f7475faaa41cd45eca12f7933c598e7cad4e89f8
MD5 hash: 1a74c8d8b74ca2411c1d3d22373a6769
humanhash: failed-white-ten-comet
File name:ba8f9e7afe5f78494c111971c39a89111ef9262bf23e8a764c6f65c818837a44
Download: download sample
Signature Lazarus
File size:1'196'032 bytes
First seen:2022-11-16 01:24:21 UTC
Last seen:2022-11-17 13:50:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f5a0b4d6fdb52793d9e7e644496ee223 (2 x Lazarus)
ssdeep 12288:eQnGcWctmPF319Ib4k24VdTl2ZYFphgIShQuSGDkDFuyjldG:ecjZtmN7jOVdB2ZYFpqhhoGYDFuo+
Threatray 2 similar samples on MalwareBazaar
TLSH T112453911E390D579D93623B654BB8A72155BBE240B7601CF225C3A353A332F32E79E1B
TrID 85.7% (.CPL) Windows Control Panel Item (generic) (197083/11/60)
4.5% (.EXE) Win64 Executable (generic) (10523/12/4)
2.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
2.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
1.9% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 74e0d8c8c8ccc8c9 (1 x Lazarus)
Reporter Arkbird_SOLG
Tags:apt DTRACK exe Lazarus

Intelligence


File Origin
# of uploads :
3
# of downloads :
353
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
lazarus
ID:
1
File name:
ba8f9e7afe5f78494c111971c39a89111ef9262bf23e8a764c6f65c818837a44
Verdict:
Malicious activity
Analysis date:
2022-11-16 01:27:04 UTC
Tags:
trojan lazarus apt

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Launching a process
Сreating synchronization primitives
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
apt greyware keylogger overlay packed shell32.dll
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Early bird code injection technique detected
Injects code into the Windows Explorer (explorer.exe)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes to foreign memory regions
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.NukeSped
Status:
Malicious
First seen:
2022-05-24 00:20:19 UTC
File Type:
PE (Exe)
Extracted files:
71
AV detection:
34 of 42 (80.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
47c1147012698048ce9e68b305ed765ba978555fe693c011547f10d79adac87e
MD5 hash:
4a85e4dfb6270ee9ca028f5cc3f9bd06
SHA1 hash:
45c48dd4602d5348d8fa0fc1dd5967fdf30634d0
Detections:
win_vsingle_auto
SH256 hash:
ba8f9e7afe5f78494c111971c39a89111ef9262bf23e8a764c6f65c818837a44
MD5 hash:
1a74c8d8b74ca2411c1d3d22373a6769
SHA1 hash:
f7475faaa41cd45eca12f7933c598e7cad4e89f8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_APT38_ValeforBeta_Mar_2021_1
Author:Arkbird_SOLG
Description:Detect ValeforBeta used in attacks against Japanese organisations by APT38
Reference:Internal Research
Rule name:Lazarus_packer_code
Author:JPCERT/CC Incident Response Group
Description:Lazarus using packer
Rule name:Lazarus_VSingle_strings
Author:JPCERT/CC Incident Response Group
Description:VSingle malware in Lazarus
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Author:Elastic Security
Description:Rule for beacon reflective loader
Rule name:win_vsingle_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.vsingle.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments