MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 cd2bc2ceb0e1b7d7c31f7a2aec7e838d3a90767ed3d02e1720170875e4a23cb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Troldesh
Vendor detections: 13
| SHA256 hash: | cd2bc2ceb0e1b7d7c31f7a2aec7e838d3a90767ed3d02e1720170875e4a23cb6 |
|---|---|
| SHA3-384 hash: | 78ed980858cb845c7ab70de3ffa22de25cbd60421e95512822c6baafb8f0d6128583a386bafd0aa81c5ceaefeb572d1e |
| SHA1 hash: | ee1c80c04d2505bd0675e42317ce702c99a9c38e |
| MD5 hash: | ce7104bc850c5a07a867cadb8f4bfa59 |
| humanhash: | tennessee-bacon-neptune-massachusetts |
| File name: | cd2bc2ceb0e1b7d7c31f7a2aec7e838d3a90767ed3d02e1720170875e4a23cb6 |
| Download: | download sample |
| Signature | Troldesh |
| File size: | 1'186'061 bytes |
| First seen: | 2021-08-30 06:25:35 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | fa2d21c960425e9ec6378d6769bb3c1a (4 x Troldesh) |
| ssdeep | 24576:0HtrdKYVVSrqGDohJ3STZG8vIn/sCBGnWsY03+C:0HtV7GwBSTc8An/4YJC |
| Threatray | 21 similar samples on MalwareBazaar |
| TLSH | T1AB45334A3D27A21FF49BCC70D663A92BDBF1BE22972829183DC0FB59C5637C08855497 |
| dhash icon | f8fcee8e8e88d0e0 (4 x Troldesh, 3 x LummaStealer, 1 x Rhadamanthys) |
| Reporter | |
| Tags: | exe signed Troldesh |
Code Signing Certificate
| Organisation: | TCBPXRFI |
|---|---|
| Issuer: | TCBPXRFI |
| Algorithm: | sha1WithRSA |
| Valid from: | 2019-02-19T16:40:08Z |
| Valid to: | 2039-12-31T23:59:59Z |
| Serial number: | -6caf808f23196773bd426117c1dbbe38 |
| Intelligence: | 2 malware samples on MalwareBazaar are signed with this code signing certificate |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | c8b2baa2930e957c9774b0512afc7d7ba3a714773a06eac15fe301a73ca8222b |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
64f7ee64a85714afa869271965ada1e1ba588b07a205a3a5eda41e9265512b0b
6192163bbb9343a274904093b94d6b12111a88bf24b58cbf9ed2c1463503e022
6d6089fee5f86170c5b3485a626cc6073631d09004f298da7b690b12a9482086
cd2bc2ceb0e1b7d7c31f7a2aec7e838d3a90767ed3d02e1720170875e4a23cb6
df2894b4298be05620b329d27bf0b45314629316fd6a082b6d90bbdfe9bf5a53
ed801a3e54843afe989aadd69cdab5e6fbf00e8e02742f354519b4b16de8f31c
62214ccdcb1052b518e6059060daec143430c1ae13a799873ebabea7f3eae217
e32998012af31476e39dedb2f725269dbd0a165d74b53a32e5e359da3a01221d
8025918ab649e33642c4eb74c2814397e971d5ab68e631e91649354c8dec2be5
c197da0fda316a92c66744bf13c77891e9f39cc10fbfebc42285a8b4761440b5
1e43c5be3ac264cf5eba9bc4647d2004012e283050924da06d5c1da18255a3b1
c659b1a6e09e7d7b98b368984d8d8e70ceee5666e3a7f54cf5a0fd90cc9f0eea
b370a4f93fb6e655f131329f027615c6828cdfc7002d7b0692f5d28e952c2194
d09c59de1d634faf6852ea9cbfa01d721c3f0a50da1fc2798acc0864409888f9
a56e155faefc72a0f5174e27670cd9f8e8c66a646744feedd0211e37f6aef6fb
d158534622b057b387a617ebe2931fef6d5c7d386b6dfbeb652c4781846f87c1
32c3fc22cab918195b3590ae17a424b5f79c145f6ee8c7d4aff376ce070248fc
62230c1651781d4ab7234fe6d747dc6cc79c1381f4ee15a84cf9a2176dcdc5d9
5ca2121b8b5edb7d1de8afd934299cc83900dd2b4ba80d95b1693b11d06155fd
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | win_troldesh_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.troldesh. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.