MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e892dbc4036d53ede078f61452515f549d8bac9a471adff6c3a9bad0b99965d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e892dbc4036d53ede078f61452515f549d8bac9a471adff6c3a9bad0b99965d2
SHA3-384 hash: b02c3047c21c6763369466f2fc1e981cbfbba5498dd301c3fa015d7489d0277557a4affb9c46237bd126de3d38e05ce5
SHA1 hash: bdd00a11bf7db90dc008ede421a6a5ef79121fd0
MD5 hash: 64a8038e7c00538cd34ae3f153acac1a
humanhash: quebec-king-glucose-nebraska
File name:SecuriteInfo.com.Mal.Cerber-AL.14582.18383
Download: download sample
File size:195'072 bytes
First seen:2020-05-12 21:48:39 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 23efc172346facf37967104d5fa96d1e
ssdeep 3072:0cVoOL9xRLnQbOrjWQkj1o6JKyk5BcVoOL/cVoOLF6z6CRV:5HRiQ01oPYCFGz
Threatray 1'529 similar samples on MalwareBazaar
TLSH 6814CF2A481EEE4BC4AF377A50333E4786809E250BCFC60599D6DCB8B55B19F251DBC2
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Cerber
Status:
Malicious
First seen:
2020-05-12 20:12:26 UTC
File Type:
PE (Dll)
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Result
Malware family:
hancitor
Score:
  10/10
Tags:
family:hancitor downloader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Suspicious use of SetThreadContext
Looks up external IP address via web service
Hancitor
Hancitor Payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DLL dll e892dbc4036d53ede078f61452515f549d8bac9a471adff6c3a9bad0b99965d2

(this sample)

Comments