MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46cb8f3e0e5bf10be49b31789332ac8a2e766a2120cb3f17d7a37ea42ef83ba7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 46cb8f3e0e5bf10be49b31789332ac8a2e766a2120cb3f17d7a37ea42ef83ba7
SHA3-384 hash: f5c8e8e9c5563a0f5acfb7a4a659ebc225e7e9fb5a64c605d96804e06918fcc53f9e7feaf8c4b3cb790596ed2f9efb48
SHA1 hash: 1a43760170ed8b925ffd4465b16eb4365e00ee92
MD5 hash: 777ea33900e10cd00c36a7ee26223867
humanhash: moon-pluto-spaghetti-two
File name:PO110629.exe
Download: download sample
File size:939'008 bytes
First seen:2020-08-05 06:30:12 UTC
Last seen:2020-08-12 10:02:19 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 12288:X+p9VFtDKdjs9jMmRF7P9VfVS024qnHOJrTGBuMq1V5p4wJ8hkdTq8Is:up77v9wmfPf4B4qnH2GBuJVJZes
Threatray 1'459 similar samples on MalwareBazaar
TLSH A6155BC2F1449A61C9694E3A8D23DA9443737D6AEF47971630D4BE2B38E31C39F35682
Reporter abuse_ch
Tags:exe


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: suntech-power.com
Sending IP: 95.211.253.210
From: Yaru Wen <Yaru.Wen@suntech-power.com>
Subject: RE: Enquiry [Purchase Order]
Attachment: PO110629.zip (contains "PO110629.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-04 20:23:35 UTC
File Type:
PE (.Net Exe)
Extracted files:
6
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Executable exe 46cb8f3e0e5bf10be49b31789332ac8a2e766a2120cb3f17d7a37ea42ef83ba7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments