🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7fbf45cb22e09288fc1c1635ac3236bfaaefd299c30873ed67c91a5248682c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 8


Intelligence 8 IOCs YARA 6 File information Comments

SHA256 hash: d7fbf45cb22e09288fc1c1635ac3236bfaaefd299c30873ed67c91a5248682c3
SHA3-384 hash: a1ac83794cb495f14bfb73c568c62e8de6cc1a7ce8dd2c76271874c19e2f3237e37f34cd0367eef820b025fd2ae568aa
SHA1 hash: 581fe54310544975f00015d115bc6f496bc0328c
MD5 hash: a45db8da2c7f9082910cb8030f312b97
humanhash: echo-eleven-muppet-louisiana
File name:Videoconferência YXQCٌ.exe
Download: download sample
Signature AZORult
File size:4'964'904 bytes
First seen:2023-04-14 13:32:41 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 15f4b05b6ecb295db03da73c01020dd2 (1 x AZORult)
ssdeep 49152:TMtn1TGAw1J+SpwyWZLAmCmPLH6aB8/QgcY0T5aYLogl87lJkqAD30tTVEvn2I5Q:IqTUyV9COaBN35aYLoCD3zvVir
TLSH T13E366C13B685643AD06B1E36487BE694AC3F7B312A17CC0F6BF41A0C4E3D641693A75B
TrID 52.6% (.CPL) Windows Control Panel Item (generic) (197083/11/60)
29.3% (.EXE) Inno Setup installer (109740/4/30)
11.0% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
2.8% (.EXE) Win64 Executable (generic) (10523/12/4)
1.2% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon f29296968e9e9ea6 (60 x AgentTesla, 37 x RedLineStealer, 35 x Formbook)
Reporter johnk3r
Tags:AZORult banker exe Grandoreiro

Intelligence


File Origin
# of uploads :
1
# of downloads :
321
Origin country :
BR BR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Videoconferência YXQCٌ.exe
Verdict:
No threats detected
Analysis date:
2023-04-14 13:35:07 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
LanguageCheck
CheckNumberOfProcessor
CheckCmdLine
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm explorer.exe fingerprint greyware keylogger overlay packed rat setupapi.dll shell32.dll
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Uses Windows timers to delay execution
Behaviour
Behavior Graph:
Verdict:
unknown
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Maps connected drives based on registry
Unpacked files
SH256 hash:
d7fbf45cb22e09288fc1c1635ac3236bfaaefd299c30873ed67c91a5248682c3
MD5 hash:
a45db8da2c7f9082910cb8030f312b97
SHA1 hash:
581fe54310544975f00015d115bc6f496bc0328c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA
Author:ditekSHen
Description:Detects Windows executables referencing non-Windows User-Agents
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:possible_trojan_banker
Author:@johnk3r
Description:Detects common strings, DLL and API in Banker_BR
Rule name:QbotStuff
Author:anonymous
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments