MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc681954f48230c5a451104f96273baaab0d30d800732af5a1cf4e1eaf49d719. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: cc681954f48230c5a451104f96273baaab0d30d800732af5a1cf4e1eaf49d719
SHA3-384 hash: 9c71507bf6ae4c1996f54ff21ec79a5ca5ae65dc92973ce0b12597767f4a39f461911eeba96c3699021dc16b514a2cd9
SHA1 hash: 7edbf247b9cb9881c1888c4feaaee5fcb3af0254
MD5 hash: 724d9557f66b00f2d74846e3e29434e6
humanhash: jig-mike-twelve-black
File name:cvf.exe
Download: download sample
File size:299'520 bytes
First seen:2025-03-12 19:07:42 UTC
Last seen:2025-03-19 07:44:37 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b10c9f38e47184aaa7cab7f4bb83709e
ssdeep 6144:UPEjjoaFQoVFUt4fg5Mdx2zJOuwUYpcNDpkhE:+EPnUt43wcomhE
TLSH T1B8546C327380C071D4922173A66C9BA6977DB9304FA595CBABC44E3BDB607C1A631F1B
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter Anonymous
Tags:exe strange


Avatar
Anonymous
Malware

Intelligence


File Origin
# of uploads :
3
# of downloads :
607
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
cvf.exe
Verdict:
Malicious activity
Analysis date:
2025-03-12 19:10:15 UTC
Tags:
telegram evasion ims-api generic stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
shell virus sage
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a file
Restart of the analyzed sample
Running batch commands
Launching a process
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
cmd findstr fingerprint lolbin microsoft_visual_cc
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Uses nslookup.exe to query domains
Uses the Telegram API (likely for C&C communication)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1636485 Sample: cvf.exe Startdate: 12/03/2025 Architecture: WINDOWS Score: 72 44 api.telegram.org 2->44 46 resolver1.opendns.com 2->46 60 Suricata IDS alerts for network traffic 2->60 62 Multi AV Scanner detection for submitted file 2->62 64 Joe Sandbox ML detected suspicious sample 2->64 9 cvf.exe 2 2->9         started        signatures3 66 Uses the Telegram API (likely for C&C communication) 44->66 process4 process5 11 cvf.exe 9 9->11         started        13 conhost.exe 9->13         started        process6 15 cmd.exe 1 11->15         started        18 cmd.exe 11->18         started        20 cmd.exe 1 11->20         started        22 6 other processes 11->22 signatures7 70 Uses nslookup.exe to query domains 15->70 24 nslookup.exe 1 15->24         started        38 2 other processes 15->38 27 nslookup.exe 1 18->27         started        40 2 other processes 18->40 29 powershell.exe 52 20->29         started        32 curl.exe 1 22->32         started        34 curl.exe 1 22->34         started        36 curl.exe 1 22->36         started        42 3 other processes 22->42 process8 dnsIp9 48 222.222.67.208.in-addr.arpa 24->48 50 myip.opendns.com 24->50 52 222.222.67.208.in-addr.arpa 27->52 54 myip.opendns.com 27->54 68 Loading BitLocker PowerShell Module 29->68 56 api.telegram.org 149.154.167.220, 443, 49712, 49715 TELEGRAMRU United Kingdom 32->56 58 127.0.0.1 unknown unknown 32->58 signatures10
Threat name:
Win32.Ransomware.Generic
Status:
Malicious
First seen:
2025-03-11 18:44:00 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Unexpected DNS network traffic destination
Verdict:
Malicious
Tags:
ip_address_lookup_website
YARA:
n/a
Unpacked files
SH256 hash:
cc681954f48230c5a451104f96273baaab0d30d800732af5a1cf4e1eaf49d719
MD5 hash:
724d9557f66b00f2d74846e3e29434e6
SHA1 hash:
7edbf247b9cb9881c1888c4feaaee5fcb3af0254
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Author:ditekSHen
Description:Detects executables using Telegram Chat Bot
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe cc681954f48230c5a451104f96273baaab0d30d800732af5a1cf4e1eaf49d719

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessW
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleWindow
KERNEL32.dll::GetConsoleOutputCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileA
KERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::FindFirstFileA

Comments