🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c920b2de025019e9a406e9b2f0ac2cbbfc18d65eac15f59ca8921c5fb4bfa240. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ArkeiStealer


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c920b2de025019e9a406e9b2f0ac2cbbfc18d65eac15f59ca8921c5fb4bfa240
SHA3-384 hash: ec197669e480141057bd27c28fa113aedac3c844336717de21cb1a3543eedf2ab58bdff811d9a3cb113038b67c139c51
SHA1 hash: a36ac4af321f97964885b801601aaee816f405d1
MD5 hash: dbe9736b562b2bcce0b531fdfeaded32
humanhash: coffee-delta-romeo-mockingbird
File name:c920b2de025019e9a406e9b2f0ac2cbbfc18d65eac15f59ca8921c5fb4bfa240
Download: download sample
Signature ArkeiStealer
File size:5'227'462 bytes
First seen:2021-11-25 12:37:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5a594319a0d69dbc452e748bcf05892e (31 x Gh0stRAT, 21 x ParallaxRAT, 15 x NetSupport)
ssdeep 98304:8Sir2GLhfKDyTuwdbvLMv4JROOLYG0WU7TKhhd1gonPcMY:LGRKDyTjDMvwOavbQWL1/cV
Threatray 117 similar samples on MalwareBazaar
TLSH T1B636123FF268A53EC46A173245B39350997BBE64A81A8C1B07FC380DCF765601E3B656
File icon (PE):PE icon
dhash icon 5050d270cccc82ae (113 x Adware.Generic, 85 x OffLoader, 48 x ValleyRAT)
Reporter 0xhido
Tags:ArkeiStealer BABADEDA-Crypter exe lockbit

Intelligence


File Origin
# of uploads :
1
# of downloads :
868
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
c920b2de025019e9a406e9b2f0ac2cbbfc18d65eac15f59ca8921c5fb4bfa240
Verdict:
Suspicious activity
Analysis date:
2021-11-25 13:50:59 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Searching for the window
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
Sending a custom TCP request
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
.NET source code contains in memory code execution
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file has a writeable .text section
Potentially malicious time measurement code found
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 528549 Sample: caYfUkPlTx Startdate: 25/11/2021 Architecture: WINDOWS Score: 80 41 Antivirus / Scanner detection for submitted sample 2->41 43 Multi AV Scanner detection for submitted file 2->43 45 Yara detected Vidar stealer 2->45 47 3 other signatures 2->47 9 caYfUkPlTx.exe 2 2->9         started        process3 file4 35 C:\Users\user\AppData\...\caYfUkPlTx.tmp, PE32 9->35 dropped 49 Obfuscated command line found 9->49 13 caYfUkPlTx.tmp 3 13 9->13         started        signatures5 process6 file7 37 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 13->37 dropped 16 caYfUkPlTx.exe 2 13->16         started        process8 file9 25 C:\Users\user\AppData\...\caYfUkPlTx.tmp, PE32 16->25 dropped 39 Obfuscated command line found 16->39 20 caYfUkPlTx.tmp 5 237 16->20         started        signatures10 process11 file12 27 C:\Users\user\...\evreporter.exe (copy), PE32 20->27 dropped 29 C:\Users\user\...\swresample-1.dll (copy), PE32 20->29 dropped 31 C:\Users\user\...\pthreadGC2.dll (copy), PE32 20->31 dropped 33 36 other files (none is malicious) 20->33 dropped 23 evreporter.exe 20->23         started        process13
Threat name:
Win32.Trojan.Convagent
Status:
Malicious
First seen:
2021-10-10 07:14:59 UTC
File Type:
PE (Exe)
AV detection:
18 of 28 (64.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Loads dropped DLL
Reads user/profile data of web browsers
Executes dropped EXE
Unpacked files
SH256 hash:
4d1fb84d2034c51f62e6e895e246d423f7b4fb2f1c2817a1aafc0a9c2cd68dc6
MD5 hash:
19d3e925bd3944acf03a70e2da39e46f
SHA1 hash:
b7710e87fecbd6abf2d1e60cfdf4f524f184850a
SH256 hash:
26e8d69435e72e93404c178540508f73a5327e3e1017668bd021a4a7e94f0c72
MD5 hash:
411a1a97353f9e332caa85bce5ba40e6
SHA1 hash:
802c612cb5199a3871246967b83efa8816d8b3c5
SH256 hash:
a444a6e54272cf070d9669ddef22611b91d7834724bedf8a397515d3269b5246
MD5 hash:
45058f287ac56af1035e970641c07cef
SHA1 hash:
523c88f59d49069d3b88c32461794e99fd10b7eb
SH256 hash:
c920b2de025019e9a406e9b2f0ac2cbbfc18d65eac15f59ca8921c5fb4bfa240
MD5 hash:
dbe9736b562b2bcce0b531fdfeaded32
SHA1 hash:
a36ac4af321f97964885b801601aaee816f405d1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments