🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd15ceb81fe452b20b552c01fd9acdbbdeeeb35881d30114b9b1af7e1039e31f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: fd15ceb81fe452b20b552c01fd9acdbbdeeeb35881d30114b9b1af7e1039e31f
SHA3-384 hash: ee441495b42b6139e895065b160b0cc46685af71640d4f641dbbefecd2f775a2894012ec370175189eb6756967e6be3c
SHA1 hash: 95907e1d57ccfd691e8608d3bbf9b6f9fa6e84ac
MD5 hash: 705c8d431b4b8fa834491ff6975a0532
humanhash: maryland-illinois-nineteen-aspen
File name:fd15ceb81fe452b20b552c01fd9acdbbdeeeb35881d30114b9b1af7e1039e31f
Download: download sample
File size:5'660'160 bytes
First seen:2022-09-24 08:13:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a0055b5d3a38e21796114cdce3937647
ssdeep 98304:8ICbLDcqmYYbLC9BEUe4sZy6lZaputk3Q5viaK:ebLY9YYbLC0Uek3L
Threatray 1 similar samples on MalwareBazaar
TLSH T12446F185EBD2C1F0D547007A8379A73A5E36872A6322D5E3FA94BD41AC716F1693C30E
TrID 44.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.1% (.EXE) Win64 Executable (generic) (10523/12/4)
9.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.9% (.FON) Windows Font (5545/9/1)
7.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
File icon (PE):PE icon
dhash icon 0180c0a4b698e400 (5 x GuLoader, 3 x LummaStealer, 1 x Kovter)
Reporter vxunderground
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
316
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file
Creating a file in the %temp% directory
Running batch commands
Creating a window
Launching a process
Сreating synchronization primitives
Creating a file in the Windows subdirectories
Moving a file to the %temp% directory
Launching cmd.exe command interpreter
Creating a file in the system32 directory
Creating a service
Launching a service
Enabling autorun for a service
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive fingerprint greyware obfuscated packed stealer
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Creates a Windows Service pointing to an executable in C:\Windows
DLL side loading technique detected
Machine Learning detection for dropped file
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses cmd line tools excessively to alter registry or file data
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 708905 Sample: 7lNHHNzhRi.exe Startdate: 24/09/2022 Architecture: WINDOWS Score: 100 70 Snort IDS alert for network traffic 2->70 72 Multi AV Scanner detection for domain / URL 2->72 74 Multi AV Scanner detection for dropped file 2->74 76 2 other signatures 2->76 7 svchost.exe 249 2->7         started        11 7lNHHNzhRi.exe 7 2->11         started        14 svchost.exe 1 2->14         started        16 2 other processes 2->16 process3 dnsIp4 66 3756298.c1.biz 185.176.43.106, 49704, 49705, 49706 ZETTA-ASBG Bulgaria 7->66 68 192.168.2.1 unknown unknown 7->68 80 System process connects to network (likely due to code injection or exploit) 7->80 82 DLL side loading technique detected 7->82 18 cmd.exe 2 7->18         started        20 cmd.exe 1 7->20         started        23 cmd.exe 2 7->23         started        28 7 other processes 7->28 60 C:\Users\user\Desktop\p2.dll, PE32 11->60 dropped 62 C:\Users\user\Desktop\p1.dll, PE32 11->62 dropped 64 C:\Users\user\AppData\Local\Temp\8B6E.tmp, Microsoft 11->64 dropped 25 cmd.exe 3 11->25         started        file5 signatures6 process7 file8 30 systeminfo.exe 1 1 18->30         started        33 conhost.exe 18->33         started        42 2 other processes 20->42 44 2 other processes 23->44 58 C:\Windows\System32\ISUpdate.dll, PE32+ 25->58 dropped 78 Uses cmd line tools excessively to alter registry or file data 25->78 35 reg.exe 1 1 25->35         started        37 expand.exe 12 25->37         started        46 10 other processes 25->46 40 systeminfo.exe 1 28->40         started        48 12 other processes 28->48 signatures9 process10 file11 84 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 30->84 86 Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines) 30->86 88 Creates a Windows Service pointing to an executable in C:\Windows 35->88 50 C:\...\a419510dc10d7a46958bf62b516d41ad.tmp, PE32 37->50 dropped 52 C:\Users\user\...\ISUpdate64.dll (copy), PE32+ 37->52 dropped 54 C:\Users\user\...\ISUpdate32.dll (copy), PE32 37->54 dropped 56 C:\...\c156222fe24e2f478ddda20c7cfde55e.tmp, PE32+ 37->56 dropped signatures12
Threat name:
Win32.Trojan.Woreflint
Status:
Malicious
First seen:
2022-08-25 21:09:53 UTC
File Type:
PE (Exe)
Extracted files:
40
AV detection:
17 of 26 (65.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
evasion persistence upx
Behaviour
Checks processor information in registry
Enumerates processes with tasklist
Enumerates system info in registry
Gathers system information
Modifies data under HKEY_USERS
Modifies registry key
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Launches sc.exe
Drops file in System32 directory
Loads dropped DLL
Creates new service(s)
Sets DLL path for service in the registry
Stops running service(s)
UPX packed file
ACProtect 1.3x - 1.4x DLL software
Unpacked files
SH256 hash:
bb859016d23a6451a9ffc003963274b1cf590439123015d4ab7b56aa2cd740ea
MD5 hash:
6a90b55e8855fbe248ae5758eac84000
SHA1 hash:
5c68f03c73fba059ee43e92235356a3376ec1c37
SH256 hash:
fd15ceb81fe452b20b552c01fd9acdbbdeeeb35881d30114b9b1af7e1039e31f
MD5 hash:
705c8d431b4b8fa834491ff6975a0532
SHA1 hash:
95907e1d57ccfd691e8608d3bbf9b6f9fa6e84ac
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments