MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ded4675716ddb6030fd4808cc764ca2b64cdf6dd095a16be2fefbf46751b273f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: ded4675716ddb6030fd4808cc764ca2b64cdf6dd095a16be2fefbf46751b273f
SHA3-384 hash: f120a49cbcef36a95c87cf2832ee24f56c196a5915cac9877786695748d6cbebae75502d594b211bec4f59cf58c9b474
SHA1 hash: 585edd1109362c271508498014ae122150a639ec
MD5 hash: bb49d1b9aee095278a24ec8dd78df43a
humanhash: fillet-muppet-lima-freddie
File name:ded4675716ddb6030fd4808cc764ca2b64cdf6dd095a16be2fefbf46751b273f
Download: download sample
File size:1'886'030 bytes
First seen:2020-06-03 09:04:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5e25413dfcc5d6c2e1cb1ef199da4ab5
ssdeep 49152:HKCsZk0gkvGs9y0hYCjyu15z+PN5YH9291hvjSugd/:KepW9y0aCjyo5z+PLYHItOua
Threatray 4 similar samples on MalwareBazaar
TLSH 1A951249EA6193F2D41900B856198FFB0D6A7C345E52AEC777C63B0E6D300C6AA33B57
Reporter raashidbhatt
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Salgorea
Status:
Malicious
First seen:
2020-06-03 17:43:24 UTC
AV detection:
44 of 48 (91.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Deletes itself
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments