MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6599619e51113f1e6a2f3d323cd3a25562cdcc732a8af7b98f4ab943eda5dad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Phorpiex


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: e6599619e51113f1e6a2f3d323cd3a25562cdcc732a8af7b98f4ab943eda5dad
SHA3-384 hash: 06eab2d6dfddf879cb75752bf93628c6f8da6a83b4cce1f2c0072906b287c7c44410f504e55674b6f1fb67efa7278988
SHA1 hash: 573c9260aba2ea932b20ea70f15c907c958d6b8b
MD5 hash: 71835588622e898f270d478218c69323
humanhash: chicken-muppet-dakota-five
File name:71835588622e898f270d478218c69323.exe
Download: download sample
Signature Phorpiex
File size:42'762 bytes
First seen:2023-11-27 15:18:57 UTC
Last seen:2023-11-27 17:17:31 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 768:K3MuYuJJXY8p5ZOcrq32UP3hBFt9iElU1lmWziu+1EcPk+4cWi:K3Mz8gPxbD1eiFOcPkw
TLSH T109131710E690D03AF4F680FFD3FB156E6C1CAFF8434658D712C665ABA7209D4A932953
TrID 35.7% (.EXE) Win32 Executable (generic) (4505/5/1)
16.3% (.ICL) Windows Icons Library (generic) (2059/9)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.8% (.EXE) Generic Win/DOS Executable (2002/3)
15.8% (.EXE) DOS Executable Generic (2000/1)
Reporter abuse_ch
Tags:exe Phorpiex

Intelligence


File Origin
# of uploads :
2
# of downloads :
306
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Worm.Phorpiex
Status:
Malicious
First seen:
2023-11-27 10:10:32 UTC
File Type:
PE (Exe)
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
e6599619e51113f1e6a2f3d323cd3a25562cdcc732a8af7b98f4ab943eda5dad
MD5 hash:
71835588622e898f270d478218c69323
SHA1 hash:
573c9260aba2ea932b20ea70f15c907c958d6b8b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Phorpiex

Executable exe e6599619e51113f1e6a2f3d323cd3a25562cdcc732a8af7b98f4ab943eda5dad

(this sample)

  
Delivery method
Distributed via web download

Comments