MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e93580fda01d2c73aa398f3cae5d1bbc05313cceb2f6d83dc24fd76bcbf72a8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 14 File information Comments

SHA256 hash: e93580fda01d2c73aa398f3cae5d1bbc05313cceb2f6d83dc24fd76bcbf72a8a
SHA3-384 hash: 8a0f1414ba488edb714d100ec1ed6b1363aa0f0e338a8f0f04c184e0220e2566359f6487c68e93addb839ee41f2fac77
SHA1 hash: ef98ed86e85a2856ed4e3961596704916bfa3776
MD5 hash: c61260095e8524ddaaa54f88d56426ae
humanhash: fifteen-lactose-island-pasta
File name:SecuriteInfo.com.BScope.Trojan.Tiggre.24145.23961
Download: download sample
File size:5'640'712 bytes
First seen:2024-03-03 15:20:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2fa0cddd0b1cd8a8a65f44e018e469d2
ssdeep 98304:TbT5MkgziflQoz5i6B4p5Eiz3wF8io5GBntE8HKw2OnkeShMsgryOo8bNK:TXaZzifWoz5iv5XfhGBtEm2470Msg6R
TLSH T17C46233D613C8B81C208E930D4B506E2BAFF2E6F470E1557123F7D527AA9B89E7851C6
File icon (PE):PE icon
dhash icon 2321c0c4e4048224
Reporter SecuriteInfoCom
Tags:exe signed

Code Signing Certificate

Organisation:ing. Michal Mutl
Issuer:Sectigo Public Code Signing CA R36
Algorithm:sha384WithRSAEncryption
Valid from:2022-02-21T00:00:00Z
Valid to:2025-02-20T23:59:59Z
Serial number: 7fb2dc3c0f1d43e1d1fe625e055c1480
Intelligence: 3 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: f2443bf7493dfec3958c203997fffe350ca80a7bd52bc39da9beb941d5de3df5
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
541
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Searching for analyzing tools
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obsidium overlay packed packed
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
36 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
Hides threads from debuggers
Malicious sample detected (through community Yara rule)
PE file has nameless sections
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade debugger and weak emulator (self modifying code)
Uses Windows timers to delay execution
Behaviour
Behavior Graph:
Verdict:
unknown
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Enumerates physical storage devices
Suspicious use of NtSetInformationThreadHideFromDebugger
Maps connected drives based on registry
Checks BIOS information in registry
Unpacked files
SH256 hash:
499b5e2efb49543ffaf59ae250bcc72ee192c2266abe3a9c86415d5667ce011a
MD5 hash:
4167a50076f3708849d60d216fdca4b9
SHA1 hash:
eb1d4d6a45863990947508434f2eece739b63068
SH256 hash:
a05dd607f2075e4d299eea8844c33744c89216fb61a95aed7fc274330ca6fdd5
MD5 hash:
7c1776dea4181666bdda4a6441e8561f
SHA1 hash:
67d24ffc7bb554d6e683bf35383f76c62acdd49f
SH256 hash:
e7b04bd9e11c842601aa6746f200ff3501cc9f1451be6d8072393ea59e828623
MD5 hash:
f4ee6d54b8e60df7056ac21ab3534b33
SHA1 hash:
9af08a625419ff481c16670244db94e0edc3d160
SH256 hash:
e93580fda01d2c73aa398f3cae5d1bbc05313cceb2f6d83dc24fd76bcbf72a8a
MD5 hash:
c61260095e8524ddaaa54f88d56426ae
SHA1 hash:
ef98ed86e85a2856ed4e3961596704916bfa3776
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:Check_Qemu_Description
Rule name:Check_VBox_Description
Rule name:Check_VBox_VideoDrivers
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:QbotStuff
Author:anonymous
Rule name:virustotal
Author:Tracel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegSetValueExW

Comments