MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5d96127b34730cf3bbbccd1c35098873fc0af897cc5d6dc3dd39a8e64c511d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 12


Intelligence 12 IOCs YARA 4 File information Comments

SHA256 hash: f5d96127b34730cf3bbbccd1c35098873fc0af897cc5d6dc3dd39a8e64c511d7
SHA3-384 hash: 2b5854c637bf4f986132eabe081fc906a42ca1f7e1cb3c317b971fd24f6dab0418513b88f4b36af051d014da91fdc19d
SHA1 hash: a8aea1abb7cf1ddb275584bb5746c97790342e80
MD5 hash: d8bf792f818877bf4848fde9511caeb8
humanhash: idaho-bakerloo-jig-nitrogen
File name:1PDF.FaturaDetay_202407.exe
Download: download sample
File size:330'975 bytes
First seen:2024-07-14 06:06:43 UTC
Last seen:2024-07-24 23:05:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c9adc83b45e363b21cd6b11b5da0501f (82 x ArkeiStealer, 60 x RecordBreaker, 46 x RedLineStealer)
ssdeep 6144:CZABbWqsE/Ao+mv8Qv0LVmwq4FU0fNoy6BLtsorUC7ggXpTILMYSQpIIQENMshQt:kANwRo+mv8QD4+0V161tTNjkIIFN5c
Threatray 682 similar samples on MalwareBazaar
TLSH T1FB64CF35B581857AC0620936885BD375B53AFF041B3C65CFB3DE3D289D333462A6A39A
TrID 92.1% (.EXE) Win32 Executable Borland Delphi 7 (664796/42/58)
1.9% (.EXE) Win32 Executable Delphi generic (14182/79/4)
1.8% (.SCR) Windows screen saver (13097/50/3)
1.3% (.EXE) DOS Borland compiled Executable (generic) (10000/1/2)
0.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
File icon (PE):PE icon
dhash icon 60d898c8d8a8c08c (7 x Formbook, 7 x SnakeKeylogger, 3 x MassLogger)
Reporter cocaman
Tags:exe Ransomware ShadowRoot

Intelligence


File Origin
# of uploads :
2
# of downloads :
558
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
f5d96127b34730cf3bbbccd1c35098873fc0af897cc5d6dc3dd39a8e64c511d7.exe
Verdict:
Malicious activity
Analysis date:
2024-07-14 06:12:37 UTC
Tags:
smtp ransomware

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
Encryption Execution Generic Static Stealth
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Delayed reading of the file
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Creating a file
Running batch commands
Modifying a system file
Creating a process from a recently created file
Creating a file in the Windows subdirectories
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Unauthorized injection to a recently created process
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
borland_delphi fingerprint installer lolbin overlay packed shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.evad
Score:
88 / 100
Signature
AI detected suspicious sample
Deletes shadow drive data (may be related to ransomware)
Detected unpacking (changes PE section rights)
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Suspicious powershell command line found
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1472809 Sample: 1PDF.FaturaDetay_202407.exe Startdate: 14/07/2024 Architecture: WINDOWS Score: 88 98 smtp.mail.ru 2->98 108 Multi AV Scanner detection for submitted file 2->108 110 Machine Learning detection for sample 2->110 112 Machine Learning detection for dropped file 2->112 114 3 other signatures 2->114 15 1PDF.FaturaDetay_202407.exe 15 8 2->15         started        18 RootDesign.exe 2->18         started        21 RootDesign.exe 2->21         started        23 svchost.exe 1 1 2->23         started        signatures3 process4 dnsIp5 92 C:\TheDream\Uninstall.exe, PE32 15->92 dropped 94 C:\TheDream\RootDesign.exe, PE32 15->94 dropped 96 C:\Users\user\AppData\Local\...\temp_0.tmp, Microsoft 15->96 dropped 26 cmd.exe 1 15->26         started        104 Deletes shadow drive data (may be related to ransomware) 18->104 29 RootDesign.exe 18->29         started        31 RootDesign.exe 21->31         started        102 127.0.0.1 unknown unknown 23->102 file6 signatures7 process8 signatures9 128 Suspicious powershell command line found 26->128 33 powershell.exe 7 26->33         started        35 svchost.exe 26->35 injected 37 conhost.exe 26->37         started        130 Deletes shadow drive data (may be related to ransomware) 29->130 39 RootDesign.exe 29->39         started        42 RootDesign.exe 31->42         started        process10 signatures11 44 powershell.exe 7 33->44         started        46 consent.exe 35->46         started        124 Deletes shadow drive data (may be related to ransomware) 39->124 49 RootDesign.exe 39->49         started        51 RootDesign.exe 42->51         started        process12 signatures13 53 RootDesign.exe 1 6 44->53         started        136 Writes to foreign memory regions 46->136 138 Deletes shadow drive data (may be related to ransomware) 49->138 56 RootDesign.exe 49->56         started        58 RootDesign.exe 51->58         started        process14 signatures15 118 Detected unpacking (changes PE section rights) 53->118 120 Machine Learning detection for dropped file 53->120 122 Deletes shadow drive data (may be related to ransomware) 53->122 60 RootDesign.exe 3 53->60         started        63 RootDesign.exe 56->63         started        65 RootDesign.exe 58->65         started        process16 signatures17 134 Deletes shadow drive data (may be related to ransomware) 60->134 67 RootDesign.exe 4 60->67         started        71 RootDesign.exe 63->71         started        73 RootDesign.exe 65->73         started        process18 dnsIp19 100 smtp.mail.ru 217.69.139.160, 49733, 49736, 49737 MAILRU-ASMailRuRU Russian Federation 67->100 116 Deletes shadow drive data (may be related to ransomware) 67->116 75 RootDesign.exe 67->75         started        78 RootDesign.exe 71->78         started        80 RootDesign.exe 73->80         started        signatures20 process21 signatures22 132 Deletes shadow drive data (may be related to ransomware) 75->132 82 RootDesign.exe 75->82         started        85 RootDesign.exe 75->85         started        87 RootDesign.exe 78->87         started        process23 signatures24 106 Deletes shadow drive data (may be related to ransomware) 82->106 89 RootDesign.exe 85->89         started        process25 signatures26 126 Deletes shadow drive data (may be related to ransomware) 89->126
Threat name:
Win32.Trojan.Sysn
Status:
Malicious
First seen:
2024-07-14 06:06:54 UTC
File Type:
PE (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Checks installed software on the system
Hide Artifacts: Hidden Window
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
ea8a595a76a8cb9731b2d8ec6b2c8abe58f2f18f9ab6e8a529e85be98adb5491
MD5 hash:
91dfcb485dd55ce1df9854851f25dbca
SHA1 hash:
b8c39335d000cc8fae1ec1cea651e5e662f4767b
SH256 hash:
f5d96127b34730cf3bbbccd1c35098873fc0af897cc5d6dc3dd39a8e64c511d7
MD5 hash:
d8bf792f818877bf4848fde9511caeb8
SHA1 hash:
a8aea1abb7cf1ddb275584bb5746c97790342e80
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
Rule name:Borland
Author:malware-lu
Rule name:NET
Author:malware-lu
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::AllocateAndInitializeSid
advapi32.dll::EqualSid
advapi32.dll::FreeSid
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
MULTIMEDIA_APICan Play Multimediagdi32.dll::StretchDIBits
winmm.dll::timeKillEvent
winmm.dll::timeSetEvent
SECURITY_BASE_APIUses Security Base APIadvapi32.dll::AdjustTokenPrivileges
advapi32.dll::GetTokenInformation
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteExA
shell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and Threadsadvapi32.dll::OpenProcessToken
kernel32.dll::OpenProcess
advapi32.dll::OpenThreadToken
kernel32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIkernel32.dll::TerminateProcess
kernel32.dll::LoadLibraryA
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::WinExec
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateDirectoryA
kernel32.dll::CreateFileA
kernel32.dll::DeleteFileA
kernel32.dll::GetWindowsDirectoryA
kernel32.dll::GetSystemDirectoryA
kernel32.dll::GetFileAttributesA
WIN_BASE_USER_APIRetrieves Account Informationkernel32.dll::GetComputerNameA
advapi32.dll::GetUserNameA
advapi32.dll::LookupPrivilegeValueA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegCreateKeyExA
advapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryInfoKeyA
advapi32.dll::RegQueryValueExA
advapi32.dll::RegSetValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments