MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f702dfddbc5b4f1d5a5a9db0a2c013900d30515e69a09420a7c3f6eaac901b12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f702dfddbc5b4f1d5a5a9db0a2c013900d30515e69a09420a7c3f6eaac901b12
SHA3-384 hash: 5be07a515670b9f23e89bfca43f372441e51a7d06961cc3b8e0cee4affd093aee5c7fb86a9e0a7a5f9341c82403efc09
SHA1 hash: 6dc93db10d46cf777f9928803157dd16dc097e79
MD5 hash: b693e3d2f2cab550ad4f8c5722776498
humanhash: fanta-social-freddie-fourteen
File name:xmlprov.dll
Download: download sample
File size:2'742'784 bytes
First seen:2021-08-30 13:33:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b5c4ed0eff83ecc32cea896df9da78b8
ssdeep 49152:xL+qLntVtOg3gJjW4UeJiGew5o/ylRbUlo60bNBUDXVFhIECIpuXo+kY8ss:tHnsg3gZHUeANwl6SuF+SFss
Threatray 30 similar samples on MalwareBazaar
TLSH T1A5C5E1ADA54432A8C05EC0388433D985F3B5681E0BF695FB71DAAB843F7B9D0DA75B01
Reporter JAMESWT_WT
Tags:dll exe KONNI

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 474031 Sample: xmlprov.dll Startdate: 30/08/2021 Architecture: WINDOWS Score: 48 27 Multi AV Scanner detection for submitted file 2->27 8 loaddll64.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        process5 16 rundll32.exe 10->16         started        18 WerFault.exe 9 12->18         started        20 WerFault.exe 9 14->20         started        process6 22 WerFault.exe 20 9 16->22         started        dnsIp7 25 192.168.2.1 unknown unknown 22->25
Threat name:
Win64.Trojan.GenericML
Status:
Malicious
First seen:
2021-07-29 20:49:00 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
26 of 46 (56.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
f702dfddbc5b4f1d5a5a9db0a2c013900d30515e69a09420a7c3f6eaac901b12
MD5 hash:
b693e3d2f2cab550ad4f8c5722776498
SHA1 hash:
6dc93db10d46cf777f9928803157dd16dc097e79
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments