MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc5a8a6ff27b6be8eb3cb77436c6d0efd293795cc5be1b3085bf6fa95b0982f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cc5a8a6ff27b6be8eb3cb77436c6d0efd293795cc5be1b3085bf6fa95b0982f4
SHA3-384 hash: 8ef6b0fb3f46e6e36c486b427b952941a10ef0bb4ffda28c90a49bb2a3060b95e2665d0848b80740c2cab5f32cb8ee84
SHA1 hash: ce8774a242f9030fa58868f646382614e5009f4b
MD5 hash: 2d15c733894eb1266da1ef256dbda9ed
humanhash: lima-tennessee-don-table
File name:2d15c733894eb1266da1ef256dbda9ed.exe
Download: download sample
Signature DanaBot
File size:77'839 bytes
First seen:2021-05-31 10:28:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 1536:2VAcMbR/YM2xtxAfdc8XK9NcZ1nt95q8+NGk/RJABcBPO:29E/ytxydcB9NgntbqxRJABcxO
TLSH 23732B11EA61C038D9E731F98AFE977DA51C5AB1134460DB93E42AF5E3682F0AC3149F
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
275
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2d15c733894eb1266da1ef256dbda9ed.exe
Verdict:
No threats detected
Analysis date:
2021-05-31 10:29:41 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe cc5a8a6ff27b6be8eb3cb77436c6d0efd293795cc5be1b3085bf6fa95b0982f4

(this sample)

  
Delivery method
Distributed via web download

Comments