MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fba31181ed1957e81c452fa1e860414d3a2bd2da470074a32f196f873a37d9ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fba31181ed1957e81c452fa1e860414d3a2bd2da470074a32f196f873a37d9ad
SHA3-384 hash: 3a06688855c9415d3b6e6e9b7998f92cf632e6e492f7781bde7e578587e6e1fccadbedfcb06c8b6744e3e3fb8cc52b6c
SHA1 hash: 78832090f1e856065de6bf1fd3c1a4884fad491a
MD5 hash: 296e55388cb802fbe261f9cd00668ed7
humanhash: march-georgia-michigan-oregon
File name:fba31181ed1957e81c452fa1e860414d3a2bd2da470074a32f196f873a37d9ad
Download: download sample
Signature HawkEye
File size:2'366'840 bytes
First seen:2020-03-26 20:51:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat)
ssdeep 49152:y1asF2eKY9RpUAPT726FrmaPjI87X2iSqT/zgNBehWve3Ysxw:y1a4bKYR7m6dzhX2iSqT/zyBeRYQw
Threatray 238 similar samples on MalwareBazaar
TLSH 8FB52301B9C5CCB2E1B30C32692696106D3DFD601E688B6F63E5B96EEB351907129B73
Reporter Marco_Ramilli
Tags:exe HawkEye

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Killmbr
Status:
Malicious
First seen:
2020-03-25 10:44:00 UTC
File Type:
PE (Exe)
Extracted files:
22
AV detection:
29 of 30 (96.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdiplusShutdown
gdiplus.dll::GdipAlloc
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::AllocConsole
KERNEL32.dll::AttachConsole
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::FreeConsole
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateHardLinkW
KERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::MoveFileW
KERNEL32.dll::MoveFileExW

Comments