MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6891f5d4c1d15cf0e820198cd140abd64106758dc19968a9b519dff85c5ec93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c6891f5d4c1d15cf0e820198cd140abd64106758dc19968a9b519dff85c5ec93
SHA3-384 hash: 1de3f1dc55004ca42b6c6285744419abbd79212fc5e406deb2f4964b55868b8d0e630840dc0014fcb22580de9fabd601
SHA1 hash: 8ac47bc638e30e42ac84e7e3c7fcb671c9c7b308
MD5 hash: 70f9b5c874247767818d2de02281fd41
humanhash: massachusetts-lithium-montana-nebraska
File name:Advanced_Office_Password_keygen_by_Lz0.exe
Download: download sample
File size:10'989'944 bytes
First seen:2020-11-25 10:42:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat)
ssdeep 196608:XIWT9wySmbdjQFt8NBC5YW86NAJFPhnX47qJC4NQ/Pm7o1YSTudHM:ie+8CeNJXsMNQ3319uds
Threatray 328 similar samples on MalwareBazaar
TLSH F6B63302F6D19131D92355B55A78BF6212BCAD600F344493BBDC2A55CD3C2E2BB29BE3
Reporter Anonymous

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
c6891f5d4c1d15cf0e820198cd140abd64106758dc19968a9b519dff85c5ec93
MD5 hash:
70f9b5c874247767818d2de02281fd41
SHA1 hash:
8ac47bc638e30e42ac84e7e3c7fcb671c9c7b308
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments