MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2e80df13f72ce8833c2b41643da4a1f99eb5af25422a40d1250a8a40cc92c2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e2e80df13f72ce8833c2b41643da4a1f99eb5af25422a40d1250a8a40cc92c2c
SHA3-384 hash: eebd0e3ea179981fd08b96867401805ed3f8868fad3e1e999f0105fa019a9fcda8738ffa840684dcdb5a55308d33a5cb
SHA1 hash: afb90efc716ffad7f9b21b3930907d08e7da400d
MD5 hash: 2b766f06adf2c73fb6da681572d72a6f
humanhash: yellow-november-angel-minnesota
File name:2b766f06adf2c73fb6da681572d72a6f
Download: download sample
File size:5'203'456 bytes
First seen:2021-06-14 09:35:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9dd8c0ff4fc84287e5b766563240f983 (3 x HawkEye, 2 x Jigsaw, 2 x njrat)
ssdeep 98304:y9wAo0zbKuJjtc95IamQEcgfrEXtutTacMm2jDltezaYPwJxv1pyGpc79m/yUGLK:ydo03KUmEcgfrItucjpoz5UxqGWmypLK
Threatray 739 similar samples on MalwareBazaar
TLSH 9F36232572178871DAD9333262A4C6358B2A6D04BEF9C7DF5A5AF7E51BB03C0B1160B3
Reporter zbetcheckin
Tags:32 exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2b766f06adf2c73fb6da681572d72a6f
Verdict:
No threats detected
Analysis date:
2021-06-14 09:40:12 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Downloader.Convagent
Status:
Malicious
First seen:
2021-05-04 14:28:31 UTC
AV detection:
9 of 47 (19.15%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Drops desktop.ini file(s)
Unpacked files
SH256 hash:
1ed4bee1de4d08b075ec700b5eacf24b6db5201c161a71106a43e8d591683368
MD5 hash:
9ad764b9dc4f44db006d6831485b8e88
SHA1 hash:
5683a7a05b7a04447708c63b5df6f8fdbc68d7c0
SH256 hash:
4786159a3be9b53425f2a6d7a4e7d46592fe56c88442695d28e20eb59420bf20
MD5 hash:
c790cde116157cafc4f1568c647683f9
SHA1 hash:
3736a707a820dd0fa74b82343e50bc94c95c3062
SH256 hash:
e2e80df13f72ce8833c2b41643da4a1f99eb5af25422a40d1250a8a40cc92c2c
MD5 hash:
2b766f06adf2c73fb6da681572d72a6f
SHA1 hash:
afb90efc716ffad7f9b21b3930907d08e7da400d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe e2e80df13f72ce8833c2b41643da4a1f99eb5af25422a40d1250a8a40cc92c2c

(this sample)

  
Delivery method
Distributed via web download

Comments