MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6d287e8934bea3f8c237e9095cfebd7e629bb2a9624eafc0b26065e0e03485f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e6d287e8934bea3f8c237e9095cfebd7e629bb2a9624eafc0b26065e0e03485f
SHA3-384 hash: 1cb1fdb98c0589893a8f2e5b4932f2ce807a257be63f127b51c3d0420a0aa93f1927f20166b6eefb17c7a21053b3b284
SHA1 hash: 578acf0b72db96256230d9000c8cd8900662c610
MD5 hash: a3fe9d23bb0b29ff622269ef37645e67
humanhash: green-coffee-wyoming-kansas
File name:a3fe9d23bb0b29ff622269ef37645e67.exe
Download: download sample
Signature RaccoonStealer
File size:596'992 bytes
First seen:2020-05-18 07:46:30 UTC
Last seen:2020-05-18 09:19:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 47cf1e6353be58392683f1d507f328ee (2 x RaccoonStealer)
ssdeep 12288:2ri/h8S51VTCPo8GTePheJdVeYdRA/8YOXkE3EVHQ4s:2e/hDVPesJkXE0lj
Threatray 321 similar samples on MalwareBazaar
TLSH B1C412327680C432C4A2C2719419EAA45F76BD2327B6569B37682F5B2F713D12FB3219
Reporter abuse_ch
Tags:exe RaccoonStealer


Avatar
abuse_ch
RaccoonStealer C2:
http://34.105.255.170/gate/log.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-18 01:03:22 UTC
File Type:
PE (Exe)
Extracted files:
22
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RaccoonStealer

Executable exe e6d287e8934bea3f8c237e9095cfebd7e629bb2a9624eafc0b26065e0e03485f

(this sample)

  
Delivery method
Distributed via web download

Comments