MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4559408b4677ad7be56e939a5cd9fa91fd79bdb46c8e28c0e9cf2b333a3519f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d4559408b4677ad7be56e939a5cd9fa91fd79bdb46c8e28c0e9cf2b333a3519f
SHA3-384 hash: c46cc2650ad15565a2bafcc51d946f844e8324953ba0f8c5bdce1a9f775c7e8e2455f3efb6fe0c97d1cc2958c198ed99
SHA1 hash: cded1e1e9153db09fed11d7ba34200c36c31cd68
MD5 hash: 16ebe24a41d31aea8fe8e17bc6ca7bc5
humanhash: india-iowa-item-mississippi
File name:steam.exe
Download: download sample
File size:73'216 bytes
First seen:2020-11-16 12:54:21 UTC
Last seen:2020-11-16 14:52:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e2795133a833f0c3eaa0391d9efd5c1e
ssdeep 1536:9O2z7oYufXkFoIEEgmxUdUj10cL+yvVK2oiz7h93cx:9O22aoIvjxUdUSM0Vi/h9Q
Threatray 1 similar samples on MalwareBazaar
TLSH C56329AB639014CDD7FB81F5C761120AD3B170221B21A3CF57A4868A2F6B9E19F3D761
Reporter JAMESWT_WT
Tags:narutomadara8877

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Running batch commands
Creating a process with a hidden window
Creating a file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected BatToExe compiled binary
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 317968 Sample: steam.exe Startdate: 16/11/2020 Architecture: WINDOWS Score: 64 13 Antivirus / Scanner detection for submitted sample 2->13 15 Multi AV Scanner detection for submitted file 2->15 17 Machine Learning detection for sample 2->17 19 Yara detected BatToExe compiled binary 2->19 7 steam.exe 5 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        process5 11 conhost.exe 9->11         started       
Threat name:
Win64.Trojan.Starter
Status:
Malicious
First seen:
2020-09-05 07:18:14 UTC
File Type:
PE+ (Exe)
Extracted files:
3
AV detection:
18 of 28 (64.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
d4559408b4677ad7be56e939a5cd9fa91fd79bdb46c8e28c0e9cf2b333a3519f
MD5 hash:
16ebe24a41d31aea8fe8e17bc6ca7bc5
SHA1 hash:
cded1e1e9153db09fed11d7ba34200c36c31cd68
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments