🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7cbbd5d3b59c1c020891ec0bd475e0e750cfe48a4ced35f66bfbc0526dd45cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d7cbbd5d3b59c1c020891ec0bd475e0e750cfe48a4ced35f66bfbc0526dd45cf
SHA3-384 hash: d1861b4d78239211d6dd3cfe6a6e4367dfd40b6ba66f7594181b529c498b5bfc4296dfa12438a8612e9e492739a12f2a
SHA1 hash: 05279a6177a0d29bb6c14b31af4e93246026522d
MD5 hash: 4533e928aa71c4db48a5d664cc937346
humanhash: november-texas-cold-bakerloo
File name:4533e928aa71c4db48a5d664cc937346.dll
Download: download sample
File size:16'325 bytes
First seen:2022-01-01 17:50:21 UTC
Last seen:2022-01-01 19:37:19 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 96:gGYrErJJxFdK7DDNUOQnr05pV4Lw5WnT3WO:gGYreU7DDNUOQrU4soWO
TLSH T15B72E94A738916FFCD7F5038014FF23E3222440D453CADAAFA91F616F61B1A97526345
Reporter abuse_ch
Tags:dll

Intelligence


File Origin
# of uploads :
2
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 546974 Sample: ww2ZLmfWGA.dll Startdate: 01/01/2022 Architecture: WINDOWS Score: 52 34 Multi AV Scanner detection for submitted file 2->34 36 Sigma detected: Suspicious Call by Ordinal 2->36 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-01-01 17:51:08 UTC
File Type:
PE (Dll)
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
d7cbbd5d3b59c1c020891ec0bd475e0e750cfe48a4ced35f66bfbc0526dd45cf
MD5 hash:
4533e928aa71c4db48a5d664cc937346
SHA1 hash:
05279a6177a0d29bb6c14b31af4e93246026522d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DLL dll d7cbbd5d3b59c1c020891ec0bd475e0e750cfe48a4ced35f66bfbc0526dd45cf

(this sample)

  
Delivery method
Distributed via web download

Comments