MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c0f964f8f96bcba4be2939d74fca291d537801737cdde729b9cc9c3aca2a16b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 10
| SHA256 hash: | c0f964f8f96bcba4be2939d74fca291d537801737cdde729b9cc9c3aca2a16b7 |
|---|---|
| SHA3-384 hash: | 2bca8702a108c759adb256d80173d836106380dbcd492e8f49b6c68758ea67dc6bc11d8173c78d1db71b180e25430610 |
| SHA1 hash: | 60abc8c92aab1b431183db265575f074ae863378 |
| MD5 hash: | 6435f7fe410afb11ad58885eeb93b23c |
| humanhash: | hamper-six-early-montana |
| File name: | file |
| Download: | download sample |
| File size: | 679'936 bytes |
| First seen: | 2022-09-16 06:14:25 UTC |
| Last seen: | 2022-09-16 06:31:07 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | fa00c14e8058bd23fb45fe5e1dc24e84 (1 x RedLineStealer) |
| ssdeep | 6144:1BYbaoykQEKFhXGonXVfmBFm7g0CzrPdhylku3fOzcVBXJMiehO:1ibJbQEKFhXBnVmmg0Cdhyu0JKE |
| TLSH | T15BE46B301F381ECCC05B59F79C96F2A48AF295797F91F4E3A47652BD8A06AA43F20351 |
| TrID | 32.2% (.EXE) Win64 Executable (generic) (10523/12/4) 20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 13.7% (.EXE) Win32 Executable (generic) (4505/5/1) 6.2% (.EXE) OS/2 Executable (generic) (2029/13) |
| Reporter | |
| Tags: | exe |
Intelligence
File Origin
# of uploads :
4
# of downloads :
312
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
file
Verdict:
Suspicious activity
Analysis date:
2022-09-16 06:26:21 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Detection(s):
Result
Verdict:
Clean
Maliciousness:
Behaviour
Searching for the window
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Sending a custom TCP request
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
Creating a file in the system32 subdirectories
Creating a file
Result
Malware family:
n/a
Score:
6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
EvasionQueryPerformanceCounter
Verdict:
No Threat
Threat level:
2/10
Confidence:
100%
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Unknown
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Contains functionality to inject code into remote processes
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2022-09-16 06:15:10 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
15 of 26 (57.69%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
5aff8630fbdac651a4026cf56124de138e88370bb831d2adc534008fa762d6a1
MD5 hash:
630354740642a098d6e1f58988134ac0
SHA1 hash:
0736b320d14b2ee9c12a41c5cca69208e2d4a115
SH256 hash:
c0f964f8f96bcba4be2939d74fca291d537801737cdde729b9cc9c3aca2a16b7
MD5 hash:
6435f7fe410afb11ad58885eeb93b23c
SHA1 hash:
60abc8c92aab1b431183db265575f074ae863378
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Dropped by
PrivateLoader
Delivery method
Distributed via drive-by
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.