🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c06cd401caaf51cd47a277f0b3c6f373776cf3c6d290ab96263dbd19a31a934d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c06cd401caaf51cd47a277f0b3c6f373776cf3c6d290ab96263dbd19a31a934d
SHA3-384 hash: 3090927dd150e2d303d2d7866dc1e2586e2fedeca6c7b871433e03605814e3990f93ceda0e29071c616674aa93b63717
SHA1 hash: 31ccfe8eae620b9d29d0e4581d6d053c51a69516
MD5 hash: e9aac23551a73d1324be7aa841ba6db4
humanhash: magnesium-nebraska-fruit-table
File name:SecuriteInfo.com.Win64.TrojanX-gen.189.28319
Download: download sample
File size:559'104 bytes
First seen:2023-12-14 04:16:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 583db94aac9c48c7c9262171c2b8c4b9
ssdeep 12288:2Tz2zZ411LME5HoQs1XKdShiVyT/fdrz6MnfHWomWwf:WqZ415XDVyDlfdnO9
Threatray 5 similar samples on MalwareBazaar
TLSH T1BEC47B19B3A843B4E1B7E178C883460BE7B178566261970F43F15BAB1F277B15B2E321
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
474
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug anti-vm control crypto greyware hacktool lolbin shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1361877 Sample: SecuriteInfo.com.Win64.Troj... Startdate: 14/12/2023 Architecture: WINDOWS Score: 56 19 Multi AV Scanner detection for submitted file 2->19 21 Machine Learning detection for sample 2->21 23 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 2->23 7 loaddll64.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 5 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Threat name:
Win64.Trojan.Znyonm
Status:
Malicious
First seen:
2023-12-14 01:27:49 UTC
File Type:
PE+ (Dll)
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Unpacked files
SH256 hash:
c06cd401caaf51cd47a277f0b3c6f373776cf3c6d290ab96263dbd19a31a934d
MD5 hash:
e9aac23551a73d1324be7aa841ba6db4
SHA1 hash:
31ccfe8eae620b9d29d0e4581d6d053c51a69516
Detections:
INDICATOR_SUSPICIOUS_References_SecTools
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe c06cd401caaf51cd47a277f0b3c6f373776cf3c6d290ab96263dbd19a31a934d

(this sample)

  
Delivery method
Distributed via web download

Comments