Created 3 years ago
d2c969098c9a689728a5f5ac942fa4f75c88738d0367d471276ac4c470504ded.dll
Remarks (2/2)
(0x02000009): DLL files normally need to be submitted with an appropriate loader. Analysis result may be incomplete if an appropriate loader was not submitted.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "52 days, 2 hours, 2 minutes, 58 seconds" to "6 hours, 14 minutes, 26 seconds" to reveal dormant functionality.
VMRay Threat Identifiers (24 rules, 43 matches)
Score | Category | Operation | Count | Classification | |
---|---|---|---|---|---|
5/5 | Extracted Configuration | QBot configuration was extracted | 1 | Banking Trojan | |
5/5 | YARA | Malicious content matched by YARA rules | 3 | Banking Trojan | |
4/5 | Injection | Writes into the memory of another process | 1 | Injector | |
4/5 | Reputation | Known malicious file | 1 | - | |
4/5 | Reputation | Contacts known malicious URL | 1 | - | |
4/5 | Reputation | Contacts known malicious IP address | 1 | - | |
4/5 | Reputation | Process command line contains known malicious IP address | 1 | - | |
3/5 | Defense Evasion | Tries to detect the presence of antivirus software | 1 | - | |
3/5 | Network Connection | Uses HTTP to upload a large amount of data. | 1 | - | |
3/5 | Heuristics | Executable is signed with a revoked certificate | 1 | - | |
Malware Configurations
Screenshots
MITRE ATT&CK™ Matrix - Windows
Sample Information
ID | #4365306 |
MD5 | |
SHA1 | |
SHA256 | |
SSDeep | |
ImpHash | |
File Name | d2c969098c9a689728a5f5ac942fa4f75c88738d0367d471276ac4c470504ded.dll |
File Size | 720.53 KB |
Sample Type | Windows DLL (x86-32) |
Verification Status | Failed |
Verification Error | The signature hash does not match the file contents |
Certificate Issuer | Sectigo Public Code Signing CA R36 |
Certificate Subject | VALENTINA SP Z O O |
Analysis Information
Creation Time | 2022-05-16 17:05 (UTC+) |
Analysis Duration | 00:04:00 |
Termination Reason | Timeout |
Number of Monitored Processes | 18 |
Execution Successful | |
Reputation Enabled | |
Built-in AV Enabled | |
Number of AV Matches | 0 |
YARA Enabled | |
Number of YARA Matches | 183 |