MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc1b51106633fe605d248dcb477e7533293e95b2d3e8fac9f4f6ac52130e8bb8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: fc1b51106633fe605d248dcb477e7533293e95b2d3e8fac9f4f6ac52130e8bb8
SHA3-384 hash: 8eaec4c6771e5d487fa44a7d8084fccf1a2bc0113153546bf5d9a454c1a7d37893603a0a0c893ba1c6fe9179baec02f7
SHA1 hash: e3127f3bfb1440d91bbab7c4cf21da8b64093db3
MD5 hash: a273f237c2c6e2cf8a4d641fc1692247
humanhash: july-equal-east-spring
File name:a2ed32e4f4a49435b6e5d04bd3430644
Download: download sample
File size:192'513 bytes
First seen:2020-11-17 14:46:52 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b71ae52e8715ee7bfaa0c9df227db54a
ssdeep 3072:ylm3zKUj6DCR5UU5+nFu9c+xPdQ2IeujFi+mWAaVJ/vZU:ylcK46zU5+s9XdQ2I3n7ZU
Threatray 79 similar samples on MalwareBazaar
TLSH A114C0C53A18994ACC7A3C3F422B427874A7D373AEF9F5149F949B8FDA6E05104AB134
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Launching the default Windows debugger (dwwin.exe)
Replacing executable files
Creating a window
Moving of the original file
Deleting of the original file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 14:48:45 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: RenamesItself
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Program crash
Deletes itself
Loads dropped DLL
Executes dropped EXE
ServiceHost packer
Unpacked files
SH256 hash:
fc1b51106633fe605d248dcb477e7533293e95b2d3e8fac9f4f6ac52130e8bb8
MD5 hash:
a273f237c2c6e2cf8a4d641fc1692247
SHA1 hash:
e3127f3bfb1440d91bbab7c4cf21da8b64093db3
SH256 hash:
d4bcb940808b515b38dcf44a6aa506732c0ce12016785fa1bcf8ec098199aaf7
MD5 hash:
e68842ea0d44cfb619179c5c057f27b9
SHA1 hash:
2dbc1fc258f797df95fe33f01eb7aa23b79ccc94
SH256 hash:
a6753614be6e7d344969df0b4f03b74494f7933a6fe435e6a281ee6f8a2cadc2
MD5 hash:
89d1df67d16a83413a8601bda060e827
SHA1 hash:
352c693f0b3aee42a1a508c8b4cd4d51a9c9f69a
SH256 hash:
dddac9cacfc78e1652b0010c4806f22d16e5abc867e3c8dc5463dadff2881792
MD5 hash:
80ead838038a6cb8a90ed1ed4ff30d46
SHA1 hash:
c6b67f2c8ee19b6d8d274c3f3347b35fdf42a3b7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments