MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9402b75daf385ed652cc1d8c3bf7f3ea306fbc16996dead5a8741eff4f54b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d9402b75daf385ed652cc1d8c3bf7f3ea306fbc16996dead5a8741eff4f54b2f
SHA3-384 hash: 90f6c8bc63d0e93e5c837c16beeb4cdf342e06cf572e7a850581ce4f3ada1c49b7c507049c89081968b236d95357e085
SHA1 hash: 64cb47c16c5636bdc5046107480aa3c7c97a2bf3
MD5 hash: f050cfe9ded513f1b8e9a4846a0fa3a7
humanhash: massachusetts-july-beer-black
File name:winmsism.bin
Download: download sample
File size:242'688 bytes
First seen:2021-03-14 13:00:41 UTC
Last seen:2021-03-14 14:39:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2af7e540704043eaf0d11a527d6e9236
ssdeep 3072:7WWoogNA31T5DpV2IMvUTxN5TS9BMGGwkdG7yBLe5ZwbLL+e3Ag0FujoFHNkyf9g:fooWAxJL2IB9NUGwkdxXAO/uUx
Threatray 1 similar samples on MalwareBazaar
TLSH CD348C11B9D2C472D073193509F8EB764A7DBD200B659EEBA3D8073E8E341D1AA31E67
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
2
# of downloads :
160
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
0e4651625abda88df56952b7e97d7fb64a3e1ea97bfe01e931d47381c0952e98
Verdict:
Malicious activity
Analysis date:
2021-03-14 12:02:57 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Reading critical registry keys
Enabling the 'hidden' option for recently created files
Delayed writing of the file
Sending a UDP request
Stealing user critical data
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 368395 Sample: winmsism.bin Startdate: 14/03/2021 Architecture: WINDOWS Score: 48 18 Multi AV Scanner detection for submitted file 2->18 6 winmsism.exe 5 2->6         started        process3 process4 8 WerFault.exe 23 9 6->8         started        12 conhost.exe 6->12         started        dnsIp5 16 192.168.2.1 unknown unknown 8->16 14 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 8->14 dropped file6
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-03-13 11:06:36 UTC
File Type:
PE (Exe)
Extracted files:
3
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
d9402b75daf385ed652cc1d8c3bf7f3ea306fbc16996dead5a8741eff4f54b2f
MD5 hash:
f050cfe9ded513f1b8e9a4846a0fa3a7
SHA1 hash:
64cb47c16c5636bdc5046107480aa3c7c97a2bf3
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments