MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbeaf4b12d6ee7771977a0d287da80ed0d7861b68ba44664aa9e4c27d11c79ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cbeaf4b12d6ee7771977a0d287da80ed0d7861b68ba44664aa9e4c27d11c79ce
SHA3-384 hash: a69f8fc1bbeeb473b08ff5d70952711e6a338288b503dd37f2411cf8466fe03a4db0cce46d663ce1505aeba60cdfe6ba
SHA1 hash: 92bc282abd71583093184d844020f367ce49030a
MD5 hash: 682ed3fab2effb467675bcdf30eb7bb9
humanhash: quiet-connecticut-pip-charlie
File name:682ed3fab2effb467675bcdf30eb7bb9.exe
Download: download sample
Signature DanaBot
File size:1'007'104 bytes
First seen:2020-05-01 12:27:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4cc6a34990e1b2c8992621852fdfa99f (1 x DanaBot)
ssdeep 24576:yAqZ1mRq50xZZNDCjVUtK7qqYyvVFtv77:ydaMQ3DCjVUtCgUVvv77
Threatray 48 similar samples on MalwareBazaar
TLSH 6125231272D2A065D47B1A346874A1B60D3FBD727330538B1B6A287F6FF16E18B91B13
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
771
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe cbeaf4b12d6ee7771977a0d287da80ed0d7861b68ba44664aa9e4c27d11c79ce

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::SetSecurityDescriptorSacl
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegSetValueExW

Comments