🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e615ea30dd37644526060689544c1a1d263b6bb77fe3084aa7883669c1fde12f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: e615ea30dd37644526060689544c1a1d263b6bb77fe3084aa7883669c1fde12f
SHA3-384 hash: 0508d2667f41e1e9e8e3806597f2861645d101dc5e23e1ff3e75be2de8f7b755503dab0e553de1f8239e7caa54844225
SHA1 hash: f1b325a6b927f62a911dd3bf199262223983fbb9
MD5 hash: 9846e2e45000984719804ec2236405bd
humanhash: twelve-pizza-carbon-mango
File name:sgrmbroker.zip
Download: download sample
Signature Lazarus
File size:2'027'008 bytes
First seen:2023-12-13 13:07:54 UTC
Last seen:2023-12-13 14:18:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c4a0213bb099203c783857a5e2fe3edc (1 x Lazarus)
ssdeep 24576:Y4ENdUyGCaeU3wxE3ICbhYrC2RQdyrE8SQsg2XOfjvJpbPTvYRrJGcti9:Y4ENdi3ICbhYrC4Qd2XwXOfXbPT2t1t
TLSH T1E995193AA240A6D4D05384B4CBE1DA91D2607C385B3533DF22D17BA69DB5CD1AFBD283
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter smica83
Tags:apt DLRAT exe Lazarus

Intelligence


File Origin
# of uploads :
2
# of downloads :
392
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Searching for the window
Creating a window
Sending an HTTP POST request
Running batch commands
Launching a process
Using the Windows Management Instrumentation requests
Creating a file
Sending an HTTP GET request
Gathering data
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
control expand lolbin masquerade remote
Malware family:
Bottom Loader
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Snort IDS alert for network traffic
Uses an obfuscated file name to hide its real file extension (double extension)
Uses known network protocols on non-standard ports
Uses whoami command line tool to query computer and username
Writes or reads registry keys via WMI
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1361426 Sample: sgrmbroker.zip.exe Startdate: 13/12/2023 Architecture: WINDOWS Score: 92 34 Snort IDS alert for network traffic 2->34 36 Malicious sample detected (through community Yara rule) 2->36 38 Antivirus detection for URL or domain 2->38 40 3 other signatures 2->40 7 sgrmbroker.zip.exe 1 2->7         started        process3 dnsIp4 28 201.77.179.66, 49700, 49701, 49702 DesktopSigmanetComunicacaoMultimidiaLtdaBR Brazil 7->28 10 cmd.exe 1 7->10         started        12 cmd.exe 1 7->12         started        15 cmd.exe 1 7->15         started        process5 signatures6 17 getmac.exe 1 10->17         started        20 conhost.exe 10->20         started        42 Uses whoami command line tool to query computer and username 12->42 22 conhost.exe 12->22         started        24 whoami.exe 1 12->24         started        26 conhost.exe 15->26         started        process7 signatures8 30 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 17->30 32 Writes or reads registry keys via WMI 17->32
Threat name:
Win64.Trojan.Nukesped
Status:
Malicious
First seen:
2023-10-31 20:13:41 UTC
File Type:
PE+ (Exe)
AV detection:
22 of 37 (59.46%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
e615ea30dd37644526060689544c1a1d263b6bb77fe3084aa7883669c1fde12f
MD5 hash:
9846e2e45000984719804ec2236405bd
SHA1 hash:
f1b325a6b927f62a911dd3bf199262223983fbb9
Detections:
MALWARE_Win_Vovalex
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MALWARE_Win_Vovalex
Author:ditekSHen
Description:Detects Vovalex ransomware
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments