MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dddf7894b2e6aafa1903384759d68455c3a4a8348a7e2da3bd272555eba9bec0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dharma


Vendor detections: 15


Intelligence 15 IOCs YARA 10 File information Comments

SHA256 hash: dddf7894b2e6aafa1903384759d68455c3a4a8348a7e2da3bd272555eba9bec0
SHA3-384 hash: 1bff9d0e545fd5c2260fb34248936716e2026c7fe1f794e50fe7f5f8671fad4e712ab71ce8fc68acf8356681a2a741b6
SHA1 hash: f1086d2f667d807dbb1aa362a7a809ea119f2565
MD5 hash: 055d1462f66a350d9886542d4d79bc2b
humanhash: vegan-eight-maine-summer
File name:05484199.exe
Download: download sample
Signature Dharma
File size:1'062'912 bytes
First seen:2023-06-09 06:52:17 UTC
Last seen:2025-01-22 10:02:05 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ad451900c0686f591cc20de73cdf7830 (1 x Dharma)
ssdeep 24576:FRYz/ERA0eMuWfHvgPw/83JI8CorP9qY0:FE/yADMuYvgP93JIc2
TLSH T18F357D22E6A390F1C0652170BD6EB7FF99273C544F1889E7A3D4361C6AB01D10DFBA96
TrID 32.2% (.EXE) Win64 Executable (generic) (10523/12/4)
20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4505/5/1)
6.2% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 0000000000000000 (902 x AgentTesla, 557 x Formbook, 316 x RedLineStealer)
Reporter Neiki
Tags:Dharma

Intelligence


File Origin
# of uploads :
2
# of downloads :
280
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
covid19
ID:
1
File name:
Ransomware.rar.zip
Verdict:
Malicious activity
Analysis date:
2021-01-16 16:28:48 UTC
Tags:
covid19 ransomware

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a file in the system32 directory
Creating a file
Launching cmd.exe command interpreter
Creating a process with a hidden window
Enabling the 'hidden' option for recently created files
Searching for synchronization primitives
Modifying an executable file
Changing a file
Creating a file in the Program Files directory
Creating a file in the Program Files subdirectories
Modifies multiple files
Replacing executable files
Moving a file to the Program Files subdirectory
Sending a custom TCP request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Creating a file in the mass storage device
Enabling autorun by creating a file
Infecting executable files
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
comsvcs.dll crysis filecoder gandcrab greyware lolbin packed ransomware rat shell32.dll
Result
Threat name:
Detection:
malicious
Classification:
rans.spre.adwa.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to modify clipboard data
Creates an autostart registry key pointing to binary in C:\Windows
Creates files in the recycle bin to hide itself
Deletes shadow drive data (may be related to ransomware)
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Drops PE files to the startup folder
Infects executable files (exe, dll, sys, html)
Malicious sample detected (through community Yara rule)
May disable shadow drive data (uses vssadmin)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has a writeable .text section
Tries to harvest and steal browser information (history, passwords, etc)
Writes many files with high entropy
Yara detected Crysis Ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 884775 Sample: 05484199.exe Startdate: 09/06/2023 Architecture: WINDOWS Score: 100 38 Malicious sample detected (through community Yara rule) 2->38 40 Antivirus / Scanner detection for submitted sample 2->40 42 Multi AV Scanner detection for dropped file 2->42 44 7 other signatures 2->44 7 05484199.exe 1 501 2->7         started        11 05484199.exe 2->11         started        13 05484199.exe 2->13         started        15 OpenWith.exe 2->15         started        process3 file4 26 C:\Windows\System32\05484199.exe, PE32 7->26 dropped 28 C:\Users\user\AppData\...\05484199.exe, PE32 7->28 dropped 30 messages.json.id-9...avirus@qq.com].ncov, COM 7->30 dropped 32 185 other files (183 malicious) 7->32 dropped 46 Creates files in the recycle bin to hide itself 7->46 48 Drops PE files to the startup folder 7->48 50 Creates an autostart registry key pointing to binary in C:\Windows 7->50 60 3 other signatures 7->60 17 cmd.exe 1 7->17         started        52 Multi AV Scanner detection for dropped file 11->52 54 Detected unpacking (changes PE section rights) 11->54 56 Detected unpacking (overwrites its own PE header) 11->56 58 Contains functionality to modify clipboard data 11->58 signatures5 process6 signatures7 34 May disable shadow drive data (uses vssadmin) 17->34 36 Deletes shadow drive data (may be related to ransomware) 17->36 20 conhost.exe 17->20         started        22 vssadmin.exe 1 17->22         started        24 mode.com 1 17->24         started        process8
Threat name:
Win32.Trojan.Brresmon
Status:
Malicious
First seen:
2020-02-14 04:36:02 UTC
File Type:
PE (Exe)
Extracted files:
32
AV detection:
31 of 37 (83.78%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
Score:
  10/10
Tags:
family:dharma persistence ransomware spyware stealer
Behaviour
Interacts with shadow copies
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in System32 directory
Adds Run key to start application
Drops desktop.ini file(s)
Checks computer location settings
Drops startup file
Reads user/profile data of web browsers
Modifies extensions of user files
Deletes shadow copies
Renames multiple (312) files with added filename extension
Renames multiple (471) files with added filename extension
Dharma
Unpacked files
SH256 hash:
eced020d68f0e0aabcf3ec6669fb0483bde09054ee6de441e56f01814de532dc
MD5 hash:
62d3e2ca818e515edbb44cad8355c91d
SHA1 hash:
40fd505ca91006e9faf842e993b1d43aa3624dc4
Detections:
win_dharma_auto
SH256 hash:
374dcffd13486c3b5d9f57a7c70366e89e87cac229f6d4e60a2ae29b79650542
MD5 hash:
3a309b570428a8d7aa208d85f6886464
SHA1 hash:
8358f3a6e1679d1283274ae1e212258e2167a65f
SH256 hash:
dddf7894b2e6aafa1903384759d68455c3a4a8348a7e2da3bd272555eba9bec0
MD5 hash:
055d1462f66a350d9886542d4d79bc2b
SHA1 hash:
f1086d2f667d807dbb1aa362a7a809ea119f2565
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MALWARE_Win_Dharma
Author:ditekSHen
Description:Detects Dharma ransomware
Rule name:MAL_Ransomware_Wadhrama
Author:Florian Roth (Nextron Systems)
Description:Detects Wadhrama Ransomware via Imphash
Reference:Internal Research
Rule name:MAL_Ransomware_Wadhrama_RID2FED
Author:Florian Roth
Description:Detects Wadhrama Ransomware via Imphash
Reference:Internal Research
Rule name:Ran_Crysis_Sep_2020_1
Author:Arkbird_SOLG
Description:Detect Crysis ransomware
Reference:Internal Research
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Windows_Ransomware_Dharma_942142e3
Author:Elastic Security
Description:Identifies DHARMA ransomware
Reference:https://blog.malwarebytes.com/threat-analysis/2019/05/threat-spotlight-crysis-aka-dharma-ransomware-causing-a-crisis-for-businesses/
Rule name:Windows_Ransomware_Dharma_aa5eefed
Author:Elastic Security
Description:Identifies DHARMA ransomware
Reference:https://blog.malwarebytes.com/threat-analysis/2019/05/threat-spotlight-crysis-aka-dharma-ransomware-causing-a-crisis-for-businesses/
Rule name:Windows_Ransomware_Dharma_b31cac3f
Author:Elastic Security
Description:Identifies DHARMA ransomware
Reference:https://blog.malwarebytes.com/threat-analysis/2019/05/threat-spotlight-crysis-aka-dharma-ransomware-causing-a-crisis-for-businesses/
Rule name:Windows_Ransomware_Dharma_e9319e4a
Author:Elastic Security
Description:Identifies DHARMA ransomware
Reference:https://blog.malwarebytes.com/threat-analysis/2019/05/threat-spotlight-crysis-aka-dharma-ransomware-causing-a-crisis-for-businesses/
Rule name:win_dharma_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dharma.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments