MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c147611e7b8819ecbf4f4130d4000c7e01c1219b95ef9d89b11f802fbb6a46b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Cosmu


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: c147611e7b8819ecbf4f4130d4000c7e01c1219b95ef9d89b11f802fbb6a46b1
SHA3-384 hash: 7db94a2df0dd95f37a80e1f7a6f93678cea01b4f2885b285df34f6c084e85d1e20c45542f8267c2ed2efe92046face2e
SHA1 hash: 53e902e6a63f4c705113c0b0adb89f64ce7400ae
MD5 hash: cdbeac271e10c789a7bea2bfbdfa6560
humanhash: zulu-coffee-berlin-coffee
File name:smalcos.exe
Download: download sample
Signature Cosmu
File size:792'555 bytes
First seen:2022-02-20 07:20:36 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 8abecba2211e61763c4c9ffcaa13369e (172 x Cosmu, 1 x Zombie, 1 x CobaltStrike)
ssdeep 24576:fMKNZz0zMQvuiMXTI0tTakmWxMb7hGfaaVFi0ClwGv4pYyz4Bhticof+21a5DFet:fMKNZz0zMQvuiMXTI0tTakmWxMb7hGfH
Threatray 2 similar samples on MalwareBazaar
TLSH T14BF46A6587B38361C1714AF1B00498842FC25AAD28677595FDD8135FA12EBEFE0EFAC1
Reporter adm1n_usa32
Tags:Cosmu exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
222
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
smalcos.exe
Verdict:
No threats detected
Analysis date:
2022-02-20 07:19:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay shell32.dll virus zombie
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Spyware.Zombie
Status:
Malicious
First seen:
2022-02-07 16:47:33 UTC
File Type:
PE (Exe)
AV detection:
25 of 28 (89.29%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Unpacked files
SH256 hash:
c147611e7b8819ecbf4f4130d4000c7e01c1219b95ef9d89b11f802fbb6a46b1
MD5 hash:
cdbeac271e10c789a7bea2bfbdfa6560
SHA1 hash:
53e902e6a63f4c705113c0b0adb89f64ce7400ae
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments