MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0621954bd329b5cabe45e92b31053627c27fa40853beb2cce2734fa677ffd93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: c0621954bd329b5cabe45e92b31053627c27fa40853beb2cce2734fa677ffd93
SHA3-384 hash: 2ba8eef7b48c82989d784060cfcee02a6e516f08acfb6189ebc777fb86cb66cf9047d788751fa87e61afb4fb864e240b
SHA1 hash: f9881d2380363cb7b3d316bbf2bde6c2d7089681
MD5 hash: db0eaad52465d5a2b86fdd6a6aa869a5
humanhash: oregon-bakerloo-neptune-fruit
File name:SharpView.exe
Download: download sample
File size:736'256 bytes
First seen:2020-12-20 14:42:01 UTC
Last seen:2025-06-13 08:18:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'854 x AgentTesla, 19'783 x Formbook, 12'304 x SnakeKeylogger)
ssdeep 12288:F6DjfgKJmEQ90TW46AvP6N/iXIFh3Wy/AUC3pWswLhQp0swq+ib7b7b7bS7qEx:F6DzgKJhyiWxiXolYx3pWswAd+J71x
TLSH C4F48E465FEC464EE2AE4E31C0744A3A80F1B8967E39E65DCAD0948B3D62BC2D530777
Reporter srcr
Tags:exe FireEye MODIFIEDSHARPVIEW


Avatar
srcr
Sample source: https://vx-underground.org/samples/Exotic/DarkHalo/DarkHalo.zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
146
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
shv.txt
Verdict:
Malicious activity
Analysis date:
2020-02-25 20:43:00 UTC
Tags:
loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Hacktool.SharpDump
Status:
Malicious
First seen:
2018-07-26 04:36:40 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  1/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
c0621954bd329b5cabe45e92b31053627c27fa40853beb2cce2734fa677ffd93
MD5 hash:
db0eaad52465d5a2b86fdd6a6aa869a5
SHA1 hash:
f9881d2380363cb7b3d316bbf2bde6c2d7089681
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments