MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c072cb1cd389ffe94439d44a984e9d03b1217d4a5d41d6a279e541d64ad74b9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: c072cb1cd389ffe94439d44a984e9d03b1217d4a5d41d6a279e541d64ad74b9c
SHA3-384 hash: 4864356a9e51107330ba68e98a9a425971e285f00d681a195a47807869d925f79a1cf3e16c33929f9b082a74e80dccd7
SHA1 hash: f40a7d9e3364288ea6ae8e440a1e08563e86d5cf
MD5 hash: 814c09aa977c4c8d302eb683ccbc2e0b
humanhash: cold-papa-south-failed
File name:48cf2749152eb05f986cc6624022123a
Download: download sample
File size:229'376 bytes
First seen:2020-11-17 12:19:52 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash a9208cbd352be04e687a14e0dfc18846 (8 x Gh0stRAT)
ssdeep 3072:KdQJW+2IpGOgxalX7vBcqeYMz77IxZa39TtsAneb/eZJ73tt4TSOB3c7TLby:sQJmIUAjBTYz77aZQ10/6J7zWSOBay
TLSH EA247C02E69045BBDDB710B444AF7B339E7A95A40B8C5ECBB788C7A544211D1FB3638B
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a service
Creating a file
Deleting a recently created file
Replacing files
Creating a file in the Program Files subdirectories
Launching a service
Launching a process
DNS request
Connection attempt
Creating a window
Enabling autorun for a service
Threat name:
Win32.Backdoor.Farfli
Status:
Malicious
First seen:
2020-11-17 12:24:36 UTC
AV detection:
24 of 28 (85.71%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Drops file in Program Files directory
Modifies service
Loads dropped DLL
Blacklisted process makes network request
Unpacked files
SH256 hash:
c072cb1cd389ffe94439d44a984e9d03b1217d4a5d41d6a279e541d64ad74b9c
MD5 hash:
814c09aa977c4c8d302eb683ccbc2e0b
SHA1 hash:
f40a7d9e3364288ea6ae8e440a1e08563e86d5cf
SH256 hash:
706cb6128b3d254f705cd65e5367b9b8cfa3445cb45e4a34a48b82243ae75aa3
MD5 hash:
9fcfe78afba95c1f3ad8e3f99c5c4636
SHA1 hash:
89dd87064a67a2efb86fdf1e91ed5edebd40f052
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Keylog_bin_mem
Author:James_inthe_box
Description:Contains Keylog

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments