MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bd20f1698163ccad3fe72522865049e454cff6fccff5834488dcbf62754500dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Stop
Vendor detections: 14
| SHA256 hash: | bd20f1698163ccad3fe72522865049e454cff6fccff5834488dcbf62754500dd |
|---|---|
| SHA3-384 hash: | 7390f94165d2df92dd4b6df6cbdcefa5af6615a0793b0d7236dce5d7fc4fe1eeb99bd74b6857c8d08f0c94395b37d419 |
| SHA1 hash: | ac2c24140346f8032ccf0887929d100ab4fb14bc |
| MD5 hash: | 92faa1ea1036735ea1e60e54677f33d0 |
| humanhash: | massachusetts-one-juliet-indigo |
| File name: | bd20f1698163ccad3fe72522865049e454cff6fccff5834488dcbf62754500dd |
| Download: | download sample |
| Signature | Stop |
| File size: | 785'920 bytes |
| First seen: | 2022-04-04 06:22:46 UTC |
| Last seen: | 2022-04-04 06:55:03 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 4b0932ad38c639ac88a395249c08ac7a (5 x Stop, 1 x Loki) |
| ssdeep | 12288:4nFlNgq4XUu9pCRFm6x2ZC7GRj8DUPRdQBkJQlaIQ37/msIKTU+L3CwsOCHdhc:4VzuATxu5Z8DUPRdQIeyrOsIKHzvC9h |
| Threatray | 1'108 similar samples on MalwareBazaar |
| TLSH | T19CF4F100BB91D039F1F326F055BA93A4B93E7AB09B3095CB62D526DE5A356E4DC3031B |
| File icon (PE): | |
| dhash icon | b2dacabecee6baa6 (148 x RedLineStealer, 145 x Stop, 100 x Smoke Loader) |
| Reporter | |
| Tags: | exe Stop |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
b203dcd879962d1b78598d18419183c92cc0ddeb5050c32f04a623a5b54d16d8
5174c6612db7aaaec2364d35ce67de1f875cff6bd8331d65514d64f2947564ea
7e87f6bb99214ff2367c661a07e5d175a6a2d0ca6a880b9947181afb7c0e7c6c
69e14b22c8cc04dfb6e39cf3873c74fcd824eabed7dc5a9555687f804c18a0c5
151c5d66399fc5b39d0388907a12af6d7dcef9fdae16f71a6491da96f77ca8a8
9869b790cc2426e4f39010a4dcbbeaa04879f8065357d249e7b1a7653b124d94
a42ad9b88509630f930d8877be30d53b6fad885e9ec9a94b38177423a15eec58
bd20f1698163ccad3fe72522865049e454cff6fccff5834488dcbf62754500dd
e823fba8474f8851df9c6555efb1a46e36d72a3296d906b4a5ccfe7a5cec06c8
055114509b3083f8c678570e21282cd46e8403d65c46e5776990de222dcd82c9
5b2bdd22b950066b2efbb15745458a1570df1bdaa33ca950f850dd9a785f0699
84d43657d9105d61785f5a98719cba3d302b480641342285bfeeaacb52c77eb4
561658b52234eef9b08d58212ca36c20983f386add8f2345b2ec14c89834a95a
270e7e63a1a6bf9e2b809ea29a3e5f75c62eb55016f95bd1a7afc774fad26f0f
85790466ce779317a44b618c3f85d9905330d9e13afbb8958e2f13b4781f2173
b41bf45f3114d995d4f4887c3a1aa2a43f4535a35d7b2fb43e09198ebe794285
e952b1646765b47da041df2ed41bcba6509fee7e878029743f071c61542f44e3
024b6d7096a4d66fee8c7371878933aef579159ab49329308496f4674730af0e
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MALWARE_Win_STOP |
|---|---|
| Author: | ditekSHen |
| Description: | Detects STOP ransomware |
| Rule name: | SUSP_XORed_URL_in_EXE |
|---|---|
| Author: | Florian Roth |
| Description: | Detects an XORed URL in an executable |
| Reference: | https://twitter.com/stvemillertime/status/1237035794973560834 |
| Rule name: | SUSP_XORed_URL_in_EXE_RID2E46 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects an XORed URL in an executable |
| Reference: | https://twitter.com/stvemillertime/status/1237035794973560834 |
| Rule name: | win_stop_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.stop. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.