MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 beaf36022ce0bd16caaee0ebfa2823de4c46e32d7f35e793af4e1538e705379f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 14 File information Comments

SHA256 hash: beaf36022ce0bd16caaee0ebfa2823de4c46e32d7f35e793af4e1538e705379f
SHA3-384 hash: e3309183040c2df2c5499cd9361566988f117047003f9225a58973d9f8ab1e4422f8eb555edf3efba9a9ebec90a3bb16
SHA1 hash: 0feb9d41f11876ba6e641bee47ef3221e8cea919
MD5 hash: bbccf12b0be14d50f955813302029b2d
humanhash: fanta-equal-wyoming-massachusetts
File name:Report on NGO Income_edit.zip
Download: download sample
File size:22'112 bytes
First seen:2024-09-19 14:33:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:1l0tdZHyktHSflbfqf81AyQkysV//cPD4m1UiomSbaDh0TNBaIm4lj:4d5yJlefFyhVHRm1dfSbayHawj
TLSH T1FAA2D1CA850931889FE016F0E1BD7A47CD7125B98AD960C9FF94792ACC62D205E8EC83
Magika zip
Reporter JAMESWT_WT
Tags:208-85-16-88 APT37 jumpshare-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
351
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Report on NGO Income_edit.xlsx.lnk
File size:67'934 bytes
SHA256 hash: 9d0807210b0615870545a18ab8eae8cecf324e89ab8d3b39a461d45cab9ef957
MD5 hash: 63dc2ab3fb59a1e5caf485b60ed1f9cc
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
Banker Stealth Pantera Dexter
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
autorun evasive masquerade persistence powershell
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-09-12 11:23:34 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
15 of 38 (39.47%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Drops startup file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:MSOffice_in_LNK
Author:@bartblaze
Description:Identifies Microsoft Office artefacts in shortcut (LNK) files.
Rule name:NET
Author:malware-lu
Rule name:PS_in_LNK
Author:@bartblaze
Description:Identifies PowerShell artefacts in shortcut (LNK) files.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments