MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e60400f9da142b7bb4e83bfa2d964e3ed937dd350d2c6881c21daa826757bac3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Blackmoon


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e60400f9da142b7bb4e83bfa2d964e3ed937dd350d2c6881c21daa826757bac3
SHA3-384 hash: 0c355d29c9a60e2f420fd3042711c834b457aa3823b20a8b87de8390123a56dff762c54c02f9cb636f26e60cc3edda24
SHA1 hash: 18449b4d78265f2cd5510102bd72e616d2d37f23
MD5 hash: 67b66d389eef5e61d46e14afccf978db
humanhash: maryland-green-solar-sad
File name:SecuriteInfo.com.Win32.Evo-gen.26930.13860
Download: download sample
Signature Blackmoon
File size:749'568 bytes
First seen:2022-12-18 20:30:58 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 4fdf46215f1c51402230679b4ee6be29 (1 x Blackmoon)
ssdeep 6144:na5MhNqhWf+Yl2l2Ly1wIYUzKxWWd0d4MuM2KfhK7gk0wzeBiUlzBeN+aYkyLVSP:na5MhNaWfBqcIWqim7s7Hc/p2QLVy
Threatray 262 similar samples on MalwareBazaar
TLSH T130F48D03BD97C0F5D74D1530147ABB3B8A7D5A424B24CFC7A364EE696D32182BA3621B
TrID 33.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
17.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
14.0% (.SCR) Windows screen saver (13097/50/3)
11.2% (.EXE) Win64 Executable (generic) (10523/12/4)
7.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
File icon (PE):PE icon
dhash icon a261bae8d2a896ca (39 x Blackmoon, 9 x Gh0stRAT, 3 x CobaltStrike)
Reporter SecuriteInfoCom
Tags:Blackmoon dll

Intelligence


File Origin
# of uploads :
1
# of downloads :
172
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Gathering data
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 769478 Sample: SecuriteInfo.com.Win32.Evo-... Startdate: 18/12/2022 Architecture: WINDOWS Score: 60 19 Antivirus / Scanner detection for submitted sample 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Machine Learning detection for sample 2->23 7 loaddll32.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 7 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Threat name:
Win32.PUA.FlyStudio
Status:
Malicious
First seen:
2020-06-11 17:24:50 UTC
File Type:
PE (Dll)
Extracted files:
50
AV detection:
22 of 48 (45.83%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
e60400f9da142b7bb4e83bfa2d964e3ed937dd350d2c6881c21daa826757bac3
MD5 hash:
67b66d389eef5e61d46e14afccf978db
SHA1 hash:
18449b4d78265f2cd5510102bd72e616d2d37f23
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments