MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e906f1c983c7c2756f4bcd4de9edb2c6e8d16c1f84a18fecf15b698a459183fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GandCrab


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: e906f1c983c7c2756f4bcd4de9edb2c6e8d16c1f84a18fecf15b698a459183fc
SHA3-384 hash: d84d8c3b550d66e06e751618b804e70c6541a9a35c040707e5688ada154ec23c54af5307c5b22d267683f8af22434d21
SHA1 hash: e47f4d11d4e7ac7d605bcc22fedc094b2009a257
MD5 hash: 832ad7fdcb28a68e778d2078136bde95
humanhash: ceiling-steak-aspen-twelve
File name:e906f1c983c7c2756f4bcd4de9edb2c6e8d16c1f84a18fecf15b698a459183fc
Download: download sample
Signature GandCrab
File size:554'952 bytes
First seen:2020-03-23 16:22:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dc817ac5a80cf719112dd0a453922ed6 (1 x GandCrab)
ssdeep 12288:NgpzGwcPp4fcK+FU58yLV7GTPoubmZYPJWwlHfS7C5X93U25mv6Oj6xlruw1aSm7:N32X+HXKO31fmNk/eSk
Threatray 474 similar samples on MalwareBazaar
TLSH 56C49F03D297EC01F82155BF24E8756302BFA7181B15DC7B59EEC6AF27F8C061A8E466
Reporter Marco_Ramilli
Tags:exe Gandcrab

Intelligence


File Origin
# of uploads :
1
# of downloads :
731
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_gandcrab_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GandCrab

Executable exe e906f1c983c7c2756f4bcd4de9edb2c6e8d16c1f84a18fecf15b698a459183fc

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments