MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4d54c9c913a87aee8f0408fd1bb613b6d89b926327b71b70cd09491bfac7eeb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hive


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: c4d54c9c913a87aee8f0408fd1bb613b6d89b926327b71b70cd09491bfac7eeb
SHA3-384 hash: b126c9a2f2252c7a32d93cb5b3183004db5c5e3c71bb9291a978d395e904aec361b8ea2e33aa4444d1c0c4650606f91e
SHA1 hash: 0878f488648abcc5f73523fcfb4267c37f27813c
MD5 hash: 88a5655e6fd20e0eebd43a0d9d6c192a
humanhash: fifteen-uniform-white-hotel
File name:c4d54c9c913a87aee8f0408fd1bb613b6d89b926327b71b70cd09491bfac7eeb.bin
Download: download sample
Signature Hive
File size:409'600 bytes
First seen:2022-03-28 23:16:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d5c5c7ed64c5f797d22b54247657c19f (1 x Hive)
ssdeep 6144:HKGBdXQ1pAqpq9aoEAKz1OWGM/gRy/xewzNNsxHmpgnFaSf:qGB6Or9aXF//xeyJiF/
Threatray 10 similar samples on MalwareBazaar
TLSH T106944947F292A0ACD16AC1788757E632F9327C0946247E7B27D0FE312F65B60A72D709
Reporter Arkbird_SOLG
Tags:exe Hive Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
435
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
SystemUptime
EvasionQueryPerformanceCounter
EvasionGetTickCount
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug expand.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Found API chain indicative of debugger detection
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Ransomware.Hive
Status:
Malicious
First seen:
2022-03-17 00:11:53 UTC
File Type:
PE+ (Exe)
AV detection:
22 of 42 (52.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
c4d54c9c913a87aee8f0408fd1bb613b6d89b926327b71b70cd09491bfac7eeb
MD5 hash:
88a5655e6fd20e0eebd43a0d9d6c192a
SHA1 hash:
0878f488648abcc5f73523fcfb4267c37f27813c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments