MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4d39db132b92514085fe269db90511484b7abe4620286f6b0a30aa475f64c3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: c4d39db132b92514085fe269db90511484b7abe4620286f6b0a30aa475f64c3e
SHA3-384 hash: 406ad0eb8d2d47dbf787fae5d9a4917c6cd607c20ea47add8985087e7df39d277c5a16f55504d7073f678c2960763f51
SHA1 hash: 0fc1feaef2b32fa7b77af80f729c761c600ef71f
MD5 hash: 46fc4776db5e40ee5e0341746ddd3443
humanhash: maine-spring-juliet-four
File name:c4d39db132b92514085fe269db90511484b7abe4620286f6b0a30aa475f64c3e
Download: download sample
File size:635'904 bytes
First seen:2023-10-20 15:43:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f77c5676d5c99563373eadafab25dc94
ssdeep 12288:g2/v9G8ZMKZ7Gse6/7f65x2xtE/9K1Ye9+bXs:x9XZKYzziKWew
TLSH T1B0D44B07F29150BCD06AC2B583576633FA72BC494625BA6B07D0BB312E75F50AF2EB05
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter hexops
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
414
Origin country :
LK LK
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
c4d39db132b92514085fe269db90511484b7abe4620286f6b0a30aa475f64c3e
Verdict:
No threats detected
Analysis date:
2023-10-20 15:46:45 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Gathering data
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
DeltaStealer
Verdict:
Malicious
Threat name:
Win64.Trojan.Znyonm
Status:
Malicious
First seen:
2023-10-19 09:18:23 UTC
File Type:
PE+ (Exe)
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
c4d39db132b92514085fe269db90511484b7abe4620286f6b0a30aa475f64c3e
MD5 hash:
46fc4776db5e40ee5e0341746ddd3443
SHA1 hash:
0fc1feaef2b32fa7b77af80f729c761c600ef71f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments