MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef2f21418e6ff5b26def9df5e5a12be498475dcd904e1e11bce087e8fb7037b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: ef2f21418e6ff5b26def9df5e5a12be498475dcd904e1e11bce087e8fb7037b6
SHA3-384 hash: b2d55361f82a82aec3fbf9b37a5e35e044bb472f76b90a8991f295ddbc806bcb3da3f37e7eba09dbc9a29bba9a6d06d0
SHA1 hash: d458c6a672fba151fe947ca3060fd19258134cd6
MD5 hash: 0079d3a1795f6cfc0390cf380328f683
humanhash: apart-idaho-north-echo
File name:0079d3a1795f6cfc0390cf380328f683
Download: download sample
File size:289'792 bytes
First seen:2021-09-18 20:11:26 UTC
Last seen:2021-09-18 20:52:08 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1bd6d269463cc591268b8d14694f5ae5 (11 x RaccoonStealer, 3 x ArkeiStealer, 2 x RedLineStealer)
ssdeep 6144:R4ZQ86LQTAT1tReKRs3crLsB7kH1TBhizZ6vXd/FFbFm+rL:aZTAT1tReyrLQ7kVT2+d9RFm+v
Threatray 4'112 similar samples on MalwareBazaar
TLSH T1EE54BF20A790C035F0B722F859B997A8A93D3EB15B3461CB52D62AFE56347E49C30397
File icon (PE):PE icon
dhash icon 1671c8bc64dcf166
Reporter zbetcheckin
Tags:32 exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
194
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
0079d3a1795f6cfc0390cf380328f683
Verdict:
Suspicious activity
Analysis date:
2021-09-18 20:15:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Connection attempt
Sending an HTTP GET request
Launching the default Windows debugger (dwwin.exe)
Malware family:
Malicious Packer
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 485756 Sample: bKBeM0qNse Startdate: 18/09/2021 Architecture: WINDOWS Score: 52 37 Multi AV Scanner detection for submitted file 2->37 39 Machine Learning detection for sample 2->39 7 bKBeM0qNse.exe 2 2->7         started        process3 dnsIp4 35 cleaner-partners.biz 193.53.127.10, 49742, 80 ASBAXETNRU Russian Federation 7->35 10 WerFault.exe 9 7->10         started        13 WerFault.exe 9 7->13         started        15 WerFault.exe 9 7->15         started        17 4 other processes 7->17 process5 file6 23 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 10->23 dropped 25 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 13->25 dropped 27 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 15->27 dropped 29 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 17->29 dropped 31 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 17->31 dropped 33 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 17->33 dropped 19 taskkill.exe 1 17->19         started        21 conhost.exe 17->21         started        process7
Threat name:
Win32.Trojan.Fragtor
Status:
Malicious
First seen:
2021-09-18 20:12:09 UTC
AV detection:
18 of 45 (40.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Deletes itself
Unpacked files
SH256 hash:
31c5144cc0a70b7f1bf4d083b63992f05be2e8f7a90c9761bab38553f28dd6a2
MD5 hash:
9966545664a799a392ece9caa612b556
SHA1 hash:
27122d6895861ae3decf9df48ea423d9deb7cc8f
SH256 hash:
ef2f21418e6ff5b26def9df5e5a12be498475dcd904e1e11bce087e8fb7037b6
MD5 hash:
0079d3a1795f6cfc0390cf380328f683
SHA1 hash:
d458c6a672fba151fe947ca3060fd19258134cd6
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe ef2f21418e6ff5b26def9df5e5a12be498475dcd904e1e11bce087e8fb7037b6

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-09-18 20:11:27 UTC

url : hxxp://194.145.227.159/pub.php?pub=mixruzki/