MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8f3b78bb9499b8df030cb6bed11cd02887fc34d2e22cfc9552c5a70140b800f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f8f3b78bb9499b8df030cb6bed11cd02887fc34d2e22cfc9552c5a70140b800f
SHA3-384 hash: 76947fa0fad2b406dda3bb91e7ee03f7e1e359a62f42eb78b9a344101e58a4bebaab62d46819385d0785c4897bf5dd25
SHA1 hash: a4a89cba7a7f8e368563b0b1c3069125ffc6aa9e
MD5 hash: c4e6da7fd1f2b6e1a51ee445c9042b3b
humanhash: speaker-georgia-kitten-seventeen
File name:b1cd8d67370a6e076f3e0238000a06f1
Download: download sample
File size:27'136 bytes
First seen:2020-11-17 15:30:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 87bed5a7cba00c7e1f4015f1bdae2183 (3'034 x Jadtre, 23 x IcedID, 17 x Blackmoon)
ssdeep 768:Yd5u7mNGtyVfYAsQGPL4vzZq2o9W7GTxGV0j:Yd5z/fDvGCq2iW7x
Threatray 1'581 similar samples on MalwareBazaar
TLSH A3C2D072CE80D0FFC0CB3432208522DB9B575A7295AA7867A710981E7DBCDD0DA7A753
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a window
Changing an executable file
DNS request
Connection attempt
Modifying an executable file
Sending an HTTP POST request
Creating a file
Running batch commands
Creating a process with a hidden window
Connection attempt to an infection source
Infecting executable files
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Virus.Wapomi
Status:
Malicious
First seen:
2020-11-17 15:37:10 UTC
AV detection:
26 of 28 (92.86%)
Threat level:
  5/5
Unpacked files
SH256 hash:
f8f3b78bb9499b8df030cb6bed11cd02887fc34d2e22cfc9552c5a70140b800f
MD5 hash:
c4e6da7fd1f2b6e1a51ee445c9042b3b
SHA1 hash:
a4a89cba7a7f8e368563b0b1c3069125ffc6aa9e
SH256 hash:
e095f757c9c3570b402ffca7393dfc34962ff1a1d6e84006938bec5d3a599a6d
MD5 hash:
a960ba061acc39ac7e21f6876b7ffd1e
SHA1 hash:
483b2ff7bd3ac69ef9b1dedfb309770eff46f365
Detections:
win_unidentified_045_g0 win_unidentified_045_auto
SH256 hash:
b939f0842eee8195d4ec8fd5738a61b006f8003a79b08facdf10f6a3b89c434c
MD5 hash:
22be378e3c3dfff505f0d10f4477af88
SHA1 hash:
92f683bf06ef2337c29537307daa0e4787434647
SH256 hash:
173428ba6b6e32a4da79b8ce6dab0b4b3a4ca80ffcfd3f6bf1cf4a914ead5db0
MD5 hash:
2979b03236383764499359647e5c17da
SHA1 hash:
9c79e0af1e8173ca83f237f8abf5b31684834abe
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments