MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bee7cc8d1343eb8931f1fdff823f7957396074edaa62a47a7382693e21858979. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: bee7cc8d1343eb8931f1fdff823f7957396074edaa62a47a7382693e21858979
SHA3-384 hash: 843f53eb79f276deaaa704a1dc509984f180c93037eaf5a8ddff4acea70cb792323faf2db379168080cb5643a0baf254
SHA1 hash: cd4544593f36e3e61134433755236a159b23e088
MD5 hash: b58b1a4ac56c26bad966c2ebcc1949df
humanhash: colorado-fruit-summer-west
File name:b58b1a4ac56c26bad966c2ebcc1949df
Download: download sample
File size:2'827'264 bytes
First seen:2021-09-04 12:38:34 UTC
Last seen:2021-09-04 14:13:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2004a5f6f543f8c26e144c1ceb66f943 (1 x DCRat, 1 x Mekotio)
ssdeep 49152:rD7Xroy0DPP23Iy5YAmw6B8If0F3IwowbGX17Jx1UoqYEww8RTUOF8LIB5YiAUkx:rDnoy0lyag6B8If0FZowSlqoq5E5aLMO
Threatray 17 similar samples on MalwareBazaar
TLSH T1BCD5F00733E2C0E8DE6790B6CA295223E7B2741507389BDF64E0592DDF93EA15B3A711
dhash icon 5cb07260c1d4e170
Reporter zbetcheckin
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
140
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
b58b1a4ac56c26bad966c2ebcc1949df
Verdict:
No threats detected
Analysis date:
2021-09-04 12:40:46 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Creating a file
Setting a keyboard event handler
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
60 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Installs a global keyboard hook
Multi AV Scanner detection for submitted file
Sample or dropped binary is a compiled AutoHotkey binary
Behaviour
Behavior Graph:
Threat name:
Win64.Malware.Bulz
Status:
Malicious
First seen:
2021-08-31 06:32:00 UTC
AV detection:
4 of 28 (14.29%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
bee7cc8d1343eb8931f1fdff823f7957396074edaa62a47a7382693e21858979
MD5 hash:
b58b1a4ac56c26bad966c2ebcc1949df
SHA1 hash:
cd4544593f36e3e61134433755236a159b23e088
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe bee7cc8d1343eb8931f1fdff823f7957396074edaa62a47a7382693e21858979

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-09-04 12:38:35 UTC

url : hxxp://kmshop.ga/users/new/grucha.exe