MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Avaddon


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2
SHA3-384 hash: ed7552adb6ead15a342a8eb314dbc3bd1f302f70289750f8362440d2695577d33ff1de3237ba078d64b365977bf29f31
SHA1 hash: 9a11a620c835f1bc8ac527a48f7c5d0443aaa9df
MD5 hash: 6fac91349f1e3171384e2c4e51814a5a
humanhash: princess-magazine-monkey-high
File name:6fac91349f1e3171384e2c4e51814a5a.exe
Download: download sample
Signature Avaddon
File size:3'721'087 bytes
First seen:2020-09-25 13:15:13 UTC
Last seen:2020-09-25 13:48:26 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b1ea5fd53e7480d5e00ebc689ced94b3 (6 x Avaddon)
ssdeep 98304:bw3OKBzMFxybbbbpNGWeEi4DtrRKm40dC:bw3y6bbbbpNYwDdC
TLSH 9B0639E6B546A1CFD45A16789527CE42A82C03F487218943FAAC79BE3F72CE31747C25
Reporter abuse_ch
Tags:Avaddon exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
224
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.Avaddon
Status:
Malicious
First seen:
2020-09-25 13:17:05 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Unpacked files
SH256 hash:
f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2
MD5 hash:
6fac91349f1e3171384e2c4e51814a5a
SHA1 hash:
9a11a620c835f1bc8ac527a48f7c5d0443aaa9df
Detections:
win_avaddon_w0
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Avaddon

Executable exe f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2

(this sample)

  
Delivery method
Distributed via web download

Comments