MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d78fd3b8cb9c914dee5e60da793e2860f7fcf0393be067876bd3a00daf37a8e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.Generic


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d78fd3b8cb9c914dee5e60da793e2860f7fcf0393be067876bd3a00daf37a8e2
SHA3-384 hash: 206c1714f85d3387f0e795e7bea1f86f23dab3299a5b346f316ea0b4ac7a16a8d9d6afebbdbae8bd11281d38b5dccb66
SHA1 hash: 1fa2dffcfa76899fd6a47a2e5eaeda463ab887c8
MD5 hash: 260d1c797dd3f814696b76a5ce505cf6
humanhash: red-angel-wolfram-sink
File name:d78fd3b8cb9c914dee5e60da793e2860f7fcf0393be067876bd3a00daf37a8e2
Download: download sample
Signature Adware.Generic
File size:893'088 bytes
First seen:2020-11-11 11:28:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3abe302b6d9a1256e6a915429af4ffd2 (271 x GuLoader, 38 x Formbook, 25 x Loki)
ssdeep 12288:I4EAmDysBW2whTmokAHSPI6vKGyvOZvZsa6eGLdap47Zt1R7X9qllrnDRxYq6:9xsBWlh8AHSPIIyvMsa6HLdTTfaBHYq6
Threatray 2 similar samples on MalwareBazaar
TLSH C51522E23612DDC6E8175BB01D339AA056964E0C8C99950A70EF3F3B7673353506A8AF
Reporter seifreed
Tags:Adware.Generic

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Adware.RedCap
Status:
Malicious
First seen:
2020-11-11 11:32:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
d78fd3b8cb9c914dee5e60da793e2860f7fcf0393be067876bd3a00daf37a8e2
MD5 hash:
260d1c797dd3f814696b76a5ce505cf6
SHA1 hash:
1fa2dffcfa76899fd6a47a2e5eaeda463ab887c8
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments