MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe33ba5d5f49662ce90089b1f64a76887b9e1eadc46b8c0eada007295f387682. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CrimsonRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fe33ba5d5f49662ce90089b1f64a76887b9e1eadc46b8c0eada007295f387682
SHA3-384 hash: bfceb62880a2b225772b68ae550b2db238818cbc5f03174a4e132ac5d8931bbd902df98282876c3445f4b8166a5bead4
SHA1 hash: e9919295fcd8c8b94ee8fce24b4d9094a9448dc7
MD5 hash: 661a0d4acac7cb0fe949c64cf4947d8d
humanhash: lamp-moon-lithium-pizza
File name:fe33ba5d5f49662ce90089b1f64a76887b9e1eadc46b8c0eada007295f387682
Download: download sample
Signature CrimsonRAT
File size:10'195'968 bytes
First seen:2020-06-10 11:28:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'610 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 3072:TJG4ShzuSgzrE6002NPxAZSK/DpaZDKmbhu0CgEPfnGB+JRaTeB:khzxq0hjWDOmm1u0fufnLza
Threatray 15 similar samples on MalwareBazaar
TLSH AAA64A413E06C153ED9A56798F12CEFE4FB0BCB8EE85925B31D17B8F3A3950052C56A8
Reporter JAMESWT_WT
Tags:CrimsonRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
570
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.CrimsonRAT
Status:
Malicious
First seen:
2020-06-08 00:42:54 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of FindShellTrayWindow
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments