MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd596fc732ff2c38357d2736eaec284ed1d93e389f26e701b2f9ceccf9abfb81. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.Generic


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: cd596fc732ff2c38357d2736eaec284ed1d93e389f26e701b2f9ceccf9abfb81
SHA3-384 hash: 77095ac08da860e58b1b58bc33ea050d815c0e9b3ad79b053a898f29e3291379cb2303fe845843a501c077102bda7869
SHA1 hash: d55a59ee6b99ad35403934156d828ab24d4d49ef
MD5 hash: ec6f8d00c4560f886c9411a17ee21633
humanhash: uncle-echo-fruit-idaho
File name:SecuriteInfo.com.Win32.Application.Agent.PYIF0X.29766.18568
Download: download sample
Signature Adware.Generic
File size:9'603'504 bytes
First seen:2024-01-26 12:45:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e569e6f445d32ba23766ad67d1e3787f (265 x Adware.Generic, 41 x RecordBreaker, 24 x RedLineStealer)
ssdeep 196608:eR21WDWfvDFL/Bs2dM4nKfwQ47OpwcsbBwVj/oCuuyqFP6oplcFWm:Osfrg2ZnZw71/oCuuyqR6S8
TLSH T13FA6233FF328A53ED1AA1A3245738250A9B7BB60750A8C1E47FC344DCF765701E3A65A
TrID 39.3% (.EXE) Inno Setup installer (107240/4/30)
21.1% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
15.7% (.EXE) InstallShield setup (43053/19/16)
15.2% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.8% (.EXE) Win64 Executable (generic) (10523/12/4)
File icon (PE):PE icon
dhash icon 5050d270cccc82ae (112 x Adware.Generic, 70 x OffLoader, 43 x LummaStealer)
Reporter SecuriteInfoCom
Tags:Adware.Generic exe signed

Code Signing Certificate

Organisation:Download Master
Issuer:Sectigo Public Code Signing CA R36
Algorithm:sha384WithRSAEncryption
Valid from:2022-09-12T00:00:00Z
Valid to:2025-09-11T23:59:59Z
Serial number: d2f856df3c4449a886e01c5178fed1ac
Intelligence: 3 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: dce61779ae6bc983a009587255fc763b85a974f305d086ec701f48a362cfd70d
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
325
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
fingerprint installer lolbin overlay packed setupapi shell32
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
30 / 100
Signature
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Behaviour
Behavior Graph:
Verdict:
unknown
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Executes dropped EXE
Loads dropped DLL
Unpacked files
SH256 hash:
02de79301ed947db6ca882cc5da8694a2f9e4c63c07c7ea88cc1985a55a82ef5
MD5 hash:
373224c5dc04b832fac8d960952bc203
SHA1 hash:
35d969e426e5750b188b8f8834368119cf9298e5
SH256 hash:
3440650aa53afb3556645f8c4f903109c4922e46aba4fa432e9fac34b8d78976
MD5 hash:
f31dbb369adae4d6a4b4b28370da4448
SHA1 hash:
3f306f68c66825e676690965377ab7f998a69521
SH256 hash:
2f26fb98dca5acf31dc598ed50d49fb043330e078b562dde07fdb6e00139d32b
MD5 hash:
b47d0d63e1a811acfff349cc96c4b893
SHA1 hash:
12c6510ccacea4f7fe80e89c8a64a99d8d456fd3
SH256 hash:
cd596fc732ff2c38357d2736eaec284ed1d93e389f26e701b2f9ceccf9abfb81
MD5 hash:
ec6f8d00c4560f886c9411a17ee21633
SHA1 hash:
d55a59ee6b99ad35403934156d828ab24d4d49ef
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments