MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e25f1039d8cff12a139762dd30c9bb255b5da9d25b34f6beac894d564e1afe02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e25f1039d8cff12a139762dd30c9bb255b5da9d25b34f6beac894d564e1afe02
SHA3-384 hash: 135b246ebcdb995cb5ae0ffbae05f2525ec9c738b836efb945602e0dc5d670b7326bb7b175f35ce5a751e2b872d3db8d
SHA1 hash: 84e6df9cfe4f2f57b99a3e89cdd2ad764093eac2
MD5 hash: 2cb5175a954e4bff190b59de45cd8e3f
humanhash: hamper-helium-harry-music
File name:B1
Download: download sample
Signature n/a
File size:262'144 bytes
First seen:2022-08-05 07:02:25 UTC
Last seen:Never
File type:unknown
MIME type:text/plain
ssdeep 6144:g+KHGgKy50h2GH1pjLTotAdhlV3fyi6/Aw5N5ir:SHZ50tLstq3xai6ogNU
TLSH T1BB446B378123BFE12779398CD0152D646C946AEBC3B8AA64FE45A871B5EC100DF2DDB1
Reporter @JAMESWT_MHT
Tags:208-67-105-125

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
IT IT
Mail intelligence
No data
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated shell32.dll
Result
Verdict:
MALICIOUS
Details
Base64 Encoded URL
Detected an ANSI or UNICODE http:// or https:// base64 encoded URL prefix.
Threat name:
Win32.Trojan.Lazy
Status:
Malicious
First seen:
2022-08-02 12:53:35 UTC
File Type:
Text (PowerShell)
AV detection:
7 of 26 (26.92%)
Threat level:
  5/5

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments