🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db846642c1c1872c6713a4194c4dcc8a8d272ff1bf0bcacc1ca1bdc3da6bc42b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 8


Intelligence 8 IOCs YARA 7 File information Comments

SHA256 hash: db846642c1c1872c6713a4194c4dcc8a8d272ff1bf0bcacc1ca1bdc3da6bc42b
SHA3-384 hash: f80731b335c459d397c0408eb0e7290a4f1c6d2257a5524edac3dd65f4789373b7600029a405d764d6e350f6303435f7
SHA1 hash: b8dd70a81279d5bb6b320d8c9e62683041107cc8
MD5 hash: edca71eda8650a2c591c37c780b6a0c5
humanhash: spaghetti-missouri-single-nitrogen
File name:edca71eda8650a2c591c37c780b6a0c5.dll
Download: download sample
Signature Lazarus
File size:1'764'352 bytes
First seen:2024-01-21 01:44:07 UTC
Last seen:2024-01-21 03:17:12 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0c014839245c109cbf47ad8c2eabf402 (1 x Lazarus)
ssdeep 24576:/wo5kB53GllG88KMRKuKtsx+G1piDKpPjKUfgm175S97FdPECJHgwa:WBBGlzgKtchXi3Ufgm9ElLdgwa
TLSH T1BB85CF98775563A9D02B863882273904E1B5F91E075785BB71CB3BC07E8F092DE39E78
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter smica83
Tags:apt exe LazarLoader Lazarus

Intelligence


File Origin
# of uploads :
2
# of downloads :
443
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
lazarloader masquerade packed packed vmprotect
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1378134 Sample: 1S15pR539y.exe Startdate: 21/01/2024 Architecture: WINDOWS Score: 48 28 Multi AV Scanner detection for submitted file 2->28 8 loaddll64.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 19 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 17 12->20         started        22 WerFault.exe 16 14->22         started        24 WerFault.exe 16 16->24         started        process6 26 WerFault.exe 20 18 18->26         started       
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2024-01-13 07:20:00 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
db846642c1c1872c6713a4194c4dcc8a8d272ff1bf0bcacc1ca1bdc3da6bc42b
MD5 hash:
edca71eda8650a2c591c37c780b6a0c5
SHA1 hash:
b8dd70a81279d5bb6b320d8c9e62683041107cc8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments