MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 10
| SHA256 hash: | d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314 |
|---|---|
| SHA3-384 hash: | 7f14960be484885886dcb0d7fde1fa976f38cb85fdd5a6f0b18f0a4d32d20a85ad123b2284b5d2e0b7b46aa781e44c9c |
| SHA1 hash: | 095d47d48ab445ec1ef4622ef424a3255c7525c7 |
| MD5 hash: | 8424ecf2f95410ceed693e7d1011d26f |
| humanhash: | mockingbird-bravo-blue-pasta |
| File name: | 8424ecf2f95410ceed693e7d1011d26f.exe |
| Download: | download sample |
| File size: | 229'376 bytes |
| First seen: | 2024-09-02 05:53:29 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 2eabe9054cad5152567f0699947a2c5b (2'852 x LummaStealer, 1'312 x Stealc, 1'026 x Healer) |
| ssdeep | 6144:CYn6RkOSvWikH/mIKE6p4vfJG6saGOBw4Bx:CVkOSvyH/mIy4ns6s30l |
| TLSH | T1322412F6CFA99AF8C4AB4F70C520555F723ACD7588E18936A20F3DE5E5AE81115E0B03 |
| TrID | 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 20.8% (.EXE) Win16 NE executable (generic) (5038/12/1) 18.6% (.EXE) Win32 Executable (generic) (4504/4/1) 8.5% (.ICL) Windows Icons Library (generic) (2059/9) 8.3% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| Reporter | |
| Tags: | exe |
Intelligence
File Origin
# of uploads :
1
# of downloads :
350
Origin country :
NLVendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
Encryption
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
microsoft_visual_cc overlay packed
Verdict:
Malicious
Labled as:
Win/malicious_confidence_90%
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Suspicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
AI detected suspicious sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Behaviour
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
PE
Detection(s):
Suspicious file
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314
MD5 hash:
8424ecf2f95410ceed693e7d1011d26f
SHA1 hash:
095d47d48ab445ec1ef4622ef424a3255c7525c7
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314
(this sample)
Delivery method
Distributed via web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.