MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efc2d3750186e0038a9bfb4e292298f92bce9f80d2af0a992a3e5fe0c9f29ecf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 1 File information Comments

SHA256 hash: efc2d3750186e0038a9bfb4e292298f92bce9f80d2af0a992a3e5fe0c9f29ecf
SHA3-384 hash: 52a2a6020e2d4cce8b4fed5336f84388029e5bbfc9b7f9295b1551d64b184c29cb24ce23d2083fd52c5a95858ac0a663
SHA1 hash: d0c66b9b5e5f58baff91f23f91a67fd3e8359662
MD5 hash: ad3a57927668a9560b5f01d7ff54c881
humanhash: violet-solar-berlin-september
File name:ad3a57927668a9560b5f01d7ff54c881.exe
Download: download sample
File size:902'871 bytes
First seen:2024-07-12 07:46:37 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f4639a0b3116c2cfc71144b88a929cfd (137 x GuLoader, 55 x Formbook, 40 x VIPKeylogger)
ssdeep 24576:MGxOmgcf/CoFPz8s43+ae4Y9hJ9HFtMr6lLwLkM0VP90esL:Xx/zCoZz943+YaJNFtM+5wL3AP9KL
Threatray 551 similar samples on MalwareBazaar
TLSH T1761523BEA3C9D877E1E312700B5905750BD25E166D98893AE7933CC8B737702AB6D306
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
File icon (PE):PE icon
dhash icon f0a29af0e8c8c0a0
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
363
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
efc2d3750186e0038a9bfb4e292298f92bce9f80d2af0a992a3e5fe0c9f29ecf.exe
Verdict:
Malicious activity
Analysis date:
2024-07-12 08:10:38 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
Encryption Execution Generic Network
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Running batch commands
Creating a process with a hidden window
Creating a process from a recently created file
Launching a process
Launching many processes
Blocking the Windows Defender launch
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
installer lolbin microsoft_visual_cc overlay packed shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis.evad
Score:
96 / 100
Signature
Adds extensions / path to Windows Defender exclusion list (Registry)
AI detected suspicious sample
Disable Microsoft Windows Malicious Software Removal Tool Heartbeat Telemetry
Disable Windows Defender real time protection (registry)
Disables the phising filter of Microsoft Edge
Disables the Smart Screen filter
Disables Windows Defender Tamper protection
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Uses cmd line tools excessively to alter registry or file data
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1472092 Sample: Ms63nDrOBa.exe Startdate: 12/07/2024 Architecture: WINDOWS Score: 96 36 Multi AV Scanner detection for dropped file 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 Machine Learning detection for sample 2->40 42 2 other signatures 2->42 7 Ms63nDrOBa.exe 1 26 2->7         started        process3 file4 28 C:\Users\user\...\win_version_csharp.exe, PE32 7->28 dropped 30 C:\Users\user\AppData\Local\...\uxdabweej.exe, PE32 7->30 dropped 32 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 7->32 dropped 34 3 other malicious files 7->34 dropped 10 cmd.exe 1 7->10         started        13 cmd.exe 1 7->13         started        process5 signatures6 44 Uses cmd line tools excessively to alter registry or file data 10->44 15 reg.exe 10->15         started        18 reg.exe 1 1 10->18         started        20 reg.exe 1 1 10->20         started        26 35 other processes 10->26 22 conhost.exe 13->22         started        24 SetACL64.exe 1 13->24         started        process7 signatures8 46 Adds extensions / path to Windows Defender exclusion list (Registry) 15->46 48 Disable Windows Defender real time protection (registry) 15->48 50 Disable Microsoft Windows Malicious Software Removal Tool Heartbeat Telemetry 18->50 52 Disables Windows Defender Tamper protection 20->52 54 Disables the phising filter of Microsoft Edge 26->54 56 Disables the Smart Screen filter 26->56
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2024-07-12 07:47:08 UTC
File Type:
PE (Exe)
Extracted files:
40
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
evasion execution trojan upx
Behaviour
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Windows security modification
Modifies Windows Defender Real-time Protection settings
Modifies Windows Defender notification settings
Modifies security service
Unpacked files
SH256 hash:
4efc87b7e585fcbe4eaed656d3dbadaec88beca7f92ca7f0089583b428a6b221
MD5 hash:
1fb64ff73938f4a04e97e5e7bf3d618c
SHA1 hash:
aa0f7db484d0c580533dec0e9964a59588c3632b
SH256 hash:
1fa9e2264b4954f01a83f6a4e8bc7982516091e0fb0c6a2f6154fa87164148b7
MD5 hash:
6b1213639bc5ffc4f1af8c17420d4b1f
SHA1 hash:
ee2d622099fb19a8ed7e1c6137f60ac86fa65486
SH256 hash:
01e72332362345c415a7edcb366d6a1b52be9ac6e946fb9da49785c140ba1a4b
MD5 hash:
b4579bc396ace8cafd9e825ff63fe244
SHA1 hash:
32a87ed28a510e3b3c06a451d1f3d0ba9faf8d9c
SH256 hash:
5a17d3c3d844c3ccd484b422789a8a5df9517ad888a93bb4bd2bff8b8956436d
MD5 hash:
fa81ea462bb76153897e3ee26319db2a
SHA1 hash:
ffe54fa36d4e8de7af595af457b2d7e5b03d9623
SH256 hash:
9152db2c0e114da0bc1e39ddd4a865f59a873780f16bfd4efaef68e3ac7e37aa
MD5 hash:
6e10c1321110b6c22212f56ba1aa4528
SHA1 hash:
da739bbd1099fab6ad78b33bfcdaad4704343681
SH256 hash:
0a357fabebabfe7b415350b34323400e6784e57ef48934a643512ed87b5366db
MD5 hash:
0ac0af4ba265ff74750285800f58f4a1
SHA1 hash:
87fa487455cf7706c766eddaa9797dcd8078721b
SH256 hash:
efc2d3750186e0038a9bfb4e292298f92bce9f80d2af0a992a3e5fe0c9f29ecf
MD5 hash:
ad3a57927668a9560b5f01d7ff54c881
SHA1 hash:
d0c66b9b5e5f58baff91f23f91a67fd3e8359662
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NSIS_April_2024
Author:NDA0N
Description:Detects NSIS installers

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteExW
SHELL32.dll::SHFileOperationW
SHELL32.dll::SHGetFileInfoW
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessW
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetDiskFreeSpaceW
KERNEL32.dll::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileW
KERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::MoveFileW
KERNEL32.dll::MoveFileExW
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExW
ADVAPI32.dll::RegDeleteKeyW
ADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryValueExW
ADVAPI32.dll::RegSetValueExW
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuW
USER32.dll::EmptyClipboard
USER32.dll::FindWindowExW
USER32.dll::OpenClipboard
USER32.dll::PeekMessageW
USER32.dll::CreateWindowExW

Comments