MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8f1569945e8adb87cb91509db4129d64a878863a347dbea1b21b70e1a21f973. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DanaBot


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: f8f1569945e8adb87cb91509db4129d64a878863a347dbea1b21b70e1a21f973
SHA3-384 hash: 8adcad12f21e1ba151f7a096eabaf392d8582ccdcb0f7f82506de646808f49a7af3e74e97e33ab12a22896001170c3f8
SHA1 hash: 208a5cad2bbd56d0d92300ce3d8ef60a3670ae0d
MD5 hash: f4106c39d7821ec3f2c4d82c1782f100
humanhash: low-romeo-whiskey-delta
File name:f4106c39d7821ec3f2c4d82c1782f100.exe
Download: download sample
Signature DanaBot
File size:1'147'392 bytes
First seen:2021-10-15 07:47:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b5be897698085ea8cfb89dc856c9bdbe (3 x RaccoonStealer, 2 x ArkeiStealer, 1 x DanaBot)
ssdeep 24576:NS5trgeHLtyo64tlrct0rpBXoda3Ftqy/10ikNNJXUZFyP8:NCPHZl6AlrctKpBYda1Yg9kNNRsl
Threatray 6'603 similar samples on MalwareBazaar
TLSH T11E3523203BA8DC74C98354704CE1AB955D3B7F22D6B4430763F4EA9E3EBAE90A6D4351
File icon (PE):PE icon
dhash icon fcfcb4f4d4d4d8c0 (19 x RedLineStealer, 16 x RaccoonStealer, 14 x Smoke Loader)
Reporter abuse_ch
Tags:DanaBot exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
321
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://protoolactive.com/bandicam-crack-full-keymaker/
Verdict:
Malicious activity
Analysis date:
2021-10-14 22:15:24 UTC
Tags:
trojan rat redline evasion loader stealer opendir vidar raccoon danabot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Enabling the 'hidden' option for recently created files
Launching a process
Creating a process with a hidden window
Creating a window
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
DanaBot
Detection:
malicious
Classification:
troj.evad
Score:
96 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Yara detected DanaBot stealer dll
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Strab
Status:
Malicious
First seen:
2021-10-15 01:12:14 UTC
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Result
Malware family:
danabot
Score:
  10/10
Tags:
family:danabot botnet:4 banker collection discovery spyware stealer trojan
Behaviour
Checks processor information in registry
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Drops file in Program Files directory
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
Checks installed software on the system
Loads dropped DLL
Reads user/profile data of web browsers
Blocklisted process makes network request
Danabot
Danabot Loader Component
Malware Config
C2 Extraction:
192.119.110.73:443
192.236.147.159:443
192.210.222.88:443
Unpacked files
SH256 hash:
4efc5002028bad510d93c791a526966cacc3b1669d7bcc1d59a18908880f3c61
MD5 hash:
6d60fb31e5d95250862ed209bb41665b
SHA1 hash:
7826045e2b25591ff0e0637c874df34e5cfe1258
SH256 hash:
e3ccfa056ea04500fb7779b865bad05f8caacc68fb1656c30cd4277f933e5b25
MD5 hash:
267bf4319cd23a177ba00122c8d9f9fd
SHA1 hash:
d26406b3985e1df42522ee0ea737d02373753791
SH256 hash:
f8f1569945e8adb87cb91509db4129d64a878863a347dbea1b21b70e1a21f973
MD5 hash:
f4106c39d7821ec3f2c4d82c1782f100
SHA1 hash:
208a5cad2bbd56d0d92300ce3d8ef60a3670ae0d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DanaBot

Executable exe f8f1569945e8adb87cb91509db4129d64a878863a347dbea1b21b70e1a21f973

(this sample)

  
Delivery method
Distributed via web download

Comments