🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc413e02defccc55f1c9925e9cf4fde4a714db1e06c6e021ddbd4b15cf2613d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Conti


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: bc413e02defccc55f1c9925e9cf4fde4a714db1e06c6e021ddbd4b15cf2613d7
SHA3-384 hash: db32ec8ff9b67c5780850bae80aff153318bfc8425fe30dff31295aa85fc8676d049c98a05eb407428b403e102a06449
SHA1 hash: 1b3611aae8621f1d135950841d6a6a8edab7ea4f
MD5 hash: e099a53fdcef7bdfb58b3a7b4f42e4d2
humanhash: lion-maryland-lemon-beer
File name:e099a53fdcef7bdfb58b3a7b4f42e4d2.dll
Download: download sample
Signature Conti
File size:220'160 bytes
First seen:2021-07-09 16:58:48 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 137fa89046164fe07e0dd776ed7a0191 (7 x Conti)
ssdeep 3072:Yw33gcHgMcWk2SglN6Ktq1YYYyFbKUqUFXGFkwuZXVjMIYvI:YwNgMNkolN611YAVKgGFjuH
Threatray 2 similar samples on MalwareBazaar
TLSH T152240801B15EDAA5D99343B88967AA03FDBB348067148EEB83844A314D0F3D576FDFA1
Reporter abuse_ch
Tags:conti dll exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
458
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
e099a53fdcef7bdfb58b3a7b4f42e4d2.dll
Verdict:
No threats detected
Analysis date:
2021-07-09 17:01:56 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Malware family:
CONTI Ransomware
Verdict:
Malicious
Result
Threat name:
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many different private IPs (likely to spread or exploit)
Found ransom note / readme
Infects executable files (exe, dll, sys, html)
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Tries to shutdown other security tools via broadcasted WM_QUERYENDSESSION
Writes many files with high entropy
Yara detected Conti ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 446541 Sample: bkDXFtQhMc.dll Startdate: 09/07/2021 Architecture: WINDOWS Score: 100 45 Antivirus / Scanner detection for submitted sample 2->45 47 Multi AV Scanner detection for submitted file 2->47 49 Found ransom note / readme 2->49 51 Yara detected Conti ransomware 2->51 7 loaddll64.exe 1 2->7         started        process3 process4 9 regsvr32.exe 32 501 7->9         started        14 iexplore.exe 1 76 7->14         started        16 cmd.exe 1 7->16         started        18 3 other processes 7->18 dnsIp5 39 192.168.2.100 unknown unknown 9->39 41 192.168.2.101 unknown unknown 9->41 43 96 other IPs or domains 9->43 25 C:\Program Files (x86)\...behaviorgraphuiReBar.au3, DOS 9->25 dropped 27 C:\...\AutoItX3.Assembly.xml, DOS 9->27 dropped 29 C:\MSOCache\All Users\...\PptLR.cab, MIPSEB 9->29 dropped 31 203 other files (201 malicious) 9->31 dropped 53 System process connects to network (likely due to code injection or exploit) 9->53 55 Connects to many different private IPs (likely to spread or exploit) 9->55 57 Tries to shutdown other security tools via broadcasted WM_QUERYENDSESSION 9->57 59 3 other signatures 9->59 20 iexplore.exe 149 14->20         started        23 rundll32.exe 16->23         started        file6 signatures7 process8 dnsIp9 33 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49997, 49998 FASTLYUS United States 20->33 35 outbrain.map.fastly.net 151.101.14.132, 443, 49994, 49995 FASTLYUS United States 20->35 37 11 other IPs or domains 20->37
Threat name:
Win64.Ransomware.Conti
Status:
Malicious
First seen:
2021-04-29 21:51:55 UTC
AV detection:
21 of 28 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:conti ransomware
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Drops file in Program Files directory
Drops file in Windows directory
Drops desktop.ini file(s)
Drops startup file
Modifies extensions of user files
Conti Ransomware
Unpacked files
SH256 hash:
bc413e02defccc55f1c9925e9cf4fde4a714db1e06c6e021ddbd4b15cf2613d7
MD5 hash:
e099a53fdcef7bdfb58b3a7b4f42e4d2
SHA1 hash:
1b3611aae8621f1d135950841d6a6a8edab7ea4f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments