MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f7561de520f21434830d40d74904e93125b76407d477411622bbd829283ba8c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Stop
Vendor detections: 19
| SHA256 hash: | f7561de520f21434830d40d74904e93125b76407d477411622bbd829283ba8c4 |
|---|---|
| SHA3-384 hash: | 2dcf62613b7690ac665b387f61fb968b5d5088dc3047e58f79810fa6472ae9e0756cf785e498e7c51c219ddb77c39dd2 |
| SHA1 hash: | 7b8c4ec9a3808eaa32ab07d1608ad275f34adbe3 |
| MD5 hash: | 8f81e96f8c96dec003b51826bbd5885f |
| humanhash: | papa-mirror-angel-blossom |
| File name: | 8f81e96f8c96dec003b51826bbd5885f.exe |
| Download: | download sample |
| Signature | Stop |
| File size: | 776'704 bytes |
| First seen: | 2024-08-13 19:57:34 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 8476831dcd3ec87a4c86e61ca01b35a0 (3 x RaccoonStealer, 3 x RedLineStealer, 1 x Smoke Loader) |
| ssdeep | 12288:VI/X+roiofZzZXvGasEKcXm/WThCFrUi/bwV5LYBYH7caEArXMViC53j:gOsiorGLEKT/WThUlbaUYH7lE005 |
| Threatray | 1'653 similar samples on MalwareBazaar |
| TLSH | T16FF4010077E0C034F1B726F649B4A7B8A52D7DB1EB35C5CB52C56AEA5638AE09C30397 |
| TrID | 46.6% (.CPL) Windows Control Panel Item (generic) (57583/11/19) 25.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 8.5% (.EXE) Win64 Executable (generic) (10523/12/4) 5.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.0% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| File icon (PE): | |
| dhash icon | 68f8e8e8aa62a499 (2 x RaccoonStealer, 1 x Stop) |
| Reporter | |
| Tags: | exe Stop |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
23ef3edf3fc3bd322e8b1a4199c0b832c89b5f2d9fb0b218168110bad22c6bf5
ab9a2ac16788b95a8f0bd270cac235e4aaba83a1772396bc97fff0925e7c704c
2cdac05088d51a5ebb646fbba3c305ec14c950dc1ce3b3d51da5aa6584774429
30089a78356dd0f6801c73349dbcbdde0e5e8b6baed69a926066ddac97d9eea4
3d1185aaeb41f59249b8ceae636ec448697236455dacfb07fb8a3460ee17dab7
2cca6cadf1f67790d0234a75ec54a6670f0503e0283b223ca04a4b9e70e97576
5f577398b47d02dbb683a2ee2a32ffc49326f3874971791646fefdb02d6796f1
f7561de520f21434830d40d74904e93125b76407d477411622bbd829283ba8c4
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Check_OutputDebugStringA_iat |
|---|
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::LoadLibraryW KERNEL32.dll::GetStartupInfoW KERNEL32.dll::GetCommandLineW |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::WriteConsoleW KERNEL32.dll::SetConsoleScreenBufferSize KERNEL32.dll::SetStdHandle KERNEL32.dll::GetConsoleCP KERNEL32.dll::GetConsoleMode |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CopyFileExA KERNEL32.dll::CreateFileW KERNEL32.dll::DeleteFileW KERNEL32.dll::GetSystemDirectoryW KERNEL32.dll::GetSystemWow64DirectoryW |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.