MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5981944f6c22372071e6086b7952be5a8bca3b4961030bea0ed4eacc8f6c096. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d5981944f6c22372071e6086b7952be5a8bca3b4961030bea0ed4eacc8f6c096
SHA3-384 hash: 863770a565a7bc06befce9ae0d81c7c1851d8f5ebedcfbeda518835edb682d7cfa40c6ffac624a0bd6fb97757febb734
SHA1 hash: 640a74e9a99b811a4b369b3c50988061b5c805c7
MD5 hash: 42f9ae998d34dd78124e26e1ca1ff02b
humanhash: lake-beer-asparagus-sink
File name:15_binder.exe
Download: download sample
File size:10'752 bytes
First seen:2020-03-24 14:36:35 UTC
Last seen:2020-03-24 16:59:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 96:0WQzqDyi58e2isUP0wPGM+MYOA/Kim5n+IyUPhdxdzM7oSPgXCExRO8gH3SC3Qvg:0WXVi/ivrLYHm5+IVPhBzr1XjYUcb0M
Threatray 32 similar samples on MalwareBazaar
TLSH 1422C821A7D8833ACEBA0F35587722500276F745D826DF6F6C84151D8D637A44AB3BF2
Reporter Racco42
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Executable exe d5981944f6c22372071e6086b7952be5a8bca3b4961030bea0ed4eacc8f6c096

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments