MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314
SHA3-384 hash: 7f14960be484885886dcb0d7fde1fa976f38cb85fdd5a6f0b18f0a4d32d20a85ad123b2284b5d2e0b7b46aa781e44c9c
SHA1 hash: 095d47d48ab445ec1ef4622ef424a3255c7525c7
MD5 hash: 8424ecf2f95410ceed693e7d1011d26f
humanhash: mockingbird-bravo-blue-pasta
File name:8424ecf2f95410ceed693e7d1011d26f.exe
Download: download sample
File size:229'376 bytes
First seen:2024-09-02 05:53:29 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2eabe9054cad5152567f0699947a2c5b (2'852 x LummaStealer, 1'312 x Stealc, 1'026 x Healer)
ssdeep 6144:CYn6RkOSvWikH/mIKE6p4vfJG6saGOBw4Bx:CVkOSvyH/mIy4ns6s30l
TLSH T1322412F6CFA99AF8C4AB4F70C520555F723ACD7588E18936A20F3DE5E5AE81115E0B03
TrID 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.3% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
350
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
Encryption
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
microsoft_visual_cc overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
AI detected suspicious sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314
MD5 hash:
8424ecf2f95410ceed693e7d1011d26f
SHA1 hash:
095d47d48ab445ec1ef4622ef424a3255c7525c7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe d7bf1b688645c58d4f203d459c1563e77694afd1020fee678e8d2a1a9e372314

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical

Comments