MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efdbfcb717b109b816e2d2f99c0d923803c70dd08fb9feb747eb90774e86116e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hive


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: efdbfcb717b109b816e2d2f99c0d923803c70dd08fb9feb747eb90774e86116e
SHA3-384 hash: 4f565cfbc107db50cc03569fc171d8b0fdf6f7a0359450dfbc818965450c61b0f6df3d671387112121d9913e78b65e23
SHA1 hash: 2bd63726ca36b312f17d591f304125a38e6e01de
MD5 hash: 2d0de4198db872ea472cb18c192e977c
humanhash: item-two-iowa-yankee
File name:efdbfcb717b109b816e2d2f99c0d923803c70dd08fb9feb747eb90774e86116e
Download: download sample
Signature Hive
File size:402'432 bytes
First seen:2022-03-26 21:31:43 UTC
Last seen:2024-07-24 22:49:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b3f6dcc1b4af5b5c34940f50a3e17687 (4 x Hive)
ssdeep 6144:9mtI0sz21JaxQ5ULYFVO8UOWGM/gRjkiIy45S8dKiwoZfp:WI1zu8iGYz1xkbYiFdp
Threatray 1 similar samples on MalwareBazaar
TLSH T162844947F2A2A0BCD16AC1788757A233F9327C0946257A7B27D0FE312F65B60A72D705
Reporter Arkbird_SOLG
Tags:exe Hive Ransomware

Intelligence


File Origin
# of uploads :
3
# of downloads :
461
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionGetTickCount
EvasionQueryPerformanceCounter
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug expand.exe filecoder greyware
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 597629 Sample: aV66IdbVUq Startdate: 26/03/2022 Architecture: WINDOWS Score: 48 10 Multi AV Scanner detection for submitted file 2->10 6 aV66IdbVUq.exe 1 2->6         started        process3 process4 8 conhost.exe 6->8         started       
Threat name:
Win64.Ransomware.Hive
Status:
Malicious
First seen:
2022-03-06 15:50:05 UTC
File Type:
PE+ (Exe)
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
efdbfcb717b109b816e2d2f99c0d923803c70dd08fb9feb747eb90774e86116e
MD5 hash:
2d0de4198db872ea472cb18c192e977c
SHA1 hash:
2bd63726ca36b312f17d591f304125a38e6e01de
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments