MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d408f5343ed5b5f9fe728f6fb44f6b3255e7ef5e97408ede945a1255c18090d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d408f5343ed5b5f9fe728f6fb44f6b3255e7ef5e97408ede945a1255c18090d3
SHA3-384 hash: 9ec7784f73213a5daa37b3cad049e5356ff158e49cab5818f92e680c8cbe7b550f0b888d16031f694a3060095c9db259
SHA1 hash: 1246a142a3f4c89fb4f199f50a7ff917b0c578e7
MD5 hash: f4b6d505f8080bf80b096c8044fc1da1
humanhash: robert-solar-mars-minnesota
File name:tgx.exe
Download: download sample
File size:1'631'232 bytes
First seen:2022-05-15 14:14:58 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3925c32bcb144b8272779e8ac801651e
ssdeep 49152:Va8vZkMQE10t9WiLzq7dH925flMYWdpvOieh1XzHJvCb4J4c:08ZfQE1q9WWq7dHglMjd5QfjJvCUT
Threatray 149 similar samples on MalwareBazaar
TLSH T1067533821816A1D3F08D2D32ADA6F40B745A4C4053CACB571DE8BF8CBDB64DD5E2BB52
TrID 32.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
28.9% (.EXE) Win32 Executable (generic) (4505/5/1)
13.0% (.EXE) OS/2 Executable (generic) (2029/13)
12.8% (.EXE) Generic Win/DOS Executable (2002/3)
12.8% (.EXE) DOS Executable Generic (2000/1)
File icon (PE):PE icon
dhash icon adc575dc6c4d80b2
Reporter obfusor
Tags:dropper exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
496
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Searching for synchronization primitives
Creating a window
Creating a file
DNS request
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
black flystudio graftor packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Antavmu
Status:
Malicious
First seen:
2022-05-07 11:21:52 UTC
File Type:
PE (Exe)
Extracted files:
75
AV detection:
23 of 41 (56.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Behaviour
Suspicious use of SetWindowsHookEx
UPX packed file
Unpacked files
SH256 hash:
7c4ee104a463a15fd055a66e44c4e99719e004fd9e254aade5ae3c862942a942
MD5 hash:
ae450659d89295583b8069e3a6939fb9
SHA1 hash:
43927550970341d2b5f53f63b6f0cbe630fdbbfd
SH256 hash:
7a5dfddb5e6284c3d520dc321310e1be5f223d78498ed1e95dac90d626c548a6
MD5 hash:
c552331ec1734ac969a82d2d0739dad5
SHA1 hash:
0b6285622ea41f75f1950a920410115d124def0d
SH256 hash:
08775d8346c5e5a6334c57cf607fa58801803adc4f749cf2be691452f0b7132a
MD5 hash:
4b4239a347850a65a72abeb15ad7d681
SHA1 hash:
688cff7646af7c90c3683506734a04c974b4e6ad
SH256 hash:
ef6bf405e8b69a1427a1f5d62a776a0992546838e90dba853b5e7deb83937341
MD5 hash:
a1724a6a9a1450f2ba3661daf2fe4d83
SHA1 hash:
ea35393903b3007926844357ab05f843c7d2d7fe
SH256 hash:
d408f5343ed5b5f9fe728f6fb44f6b3255e7ef5e97408ede945a1255c18090d3
MD5 hash:
f4b6d505f8080bf80b096c8044fc1da1
SHA1 hash:
1246a142a3f4c89fb4f199f50a7ff917b0c578e7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments