🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9b72cfc16e9a8df3cdcc4ca6dee4b567d10d1acd72a31623da92f5d62ff7629. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c9b72cfc16e9a8df3cdcc4ca6dee4b567d10d1acd72a31623da92f5d62ff7629
SHA3-384 hash: 7e7417e8c183eece7c3cad35540489f60071ee7ae7fd635f3d4b2a6862a3a6cb4c1ac1c61ca170755278b41d5d2de4f3
SHA1 hash: 8b167fd4bc6ce88c54a4c04dc45924e1e4ec3992
MD5 hash: aeac6f569fb9a7d3f32517aa16e430d6
humanhash: chicken-kentucky-sad-ceiling
File name:c9b72cfc16e9a8df3cdcc4ca6dee4b567d10d1acd72a31623da92f5d62ff7629
Download: download sample
Signature Lazarus
File size:1'516 bytes
First seen:2021-05-11 07:01:21 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/octet-stream
ssdeep 24:8uRZ9H8AQKV+/eMFwcFlRAE4I02PXQaR3+P/ZbdtCGO+/efm:8IHbhYwKRAbIpXv3yVDvO5
TLSH 7A31E00529E61725D3738D3700EEF2568775BA66E8A3CFAC519053CC1C69210F835E3B
Reporter JAMESWT_WT
Tags:apt Lazarus link pwbonus2021

Intelligence


File Origin
# of uploads :
1
# of downloads :
208
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Binary.Trojan.Nioc
Status:
Malicious
First seen:
2021-05-11 07:02:19 UTC
File Type:
Binary
AV detection:
6 of 47 (12.77%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments