MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7f93e079c0b31b91af8397148831eaaf2d73be934a460959a69e8b064531fe0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ISRStealer


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f7f93e079c0b31b91af8397148831eaaf2d73be934a460959a69e8b064531fe0
SHA3-384 hash: f7e11a4a4ed146008a8ec4ea00a381d22250bd018c8ec69a262d62922512361d93e0f4455a403c85f27661a2696ec5ca
SHA1 hash: cfd3afe5465f2bb74dc897658e484b84cff2a52d
MD5 hash: 2c55f588a608cd3c8fbdf2c604a3fc26
humanhash: cola-stream-montana-india
File name:sample quotation.zip
Download: download sample
Signature ISRStealer
File size:633'442 bytes
First seen:2020-06-25 09:33:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:NWevKd5OKHqdg3q/vWJOREigNeFykJAbOqDWP2BXspAkYlDBf:4y05OKKp/vEO+igNeFBJAa6WP2xr/
TLSH D6D423338FBD03D511471CFCB2CD9ABA346FE8DB5C8B8926B5386694470C6374A94AC6
Reporter abuse_ch
Tags:ISRStealer zip


Avatar
abuse_ch
Malspam distributing ISRStealer:

HELO: seguramenteatelier.pt
Sending IP: 156.96.118.33
From: Procure@seguramenteatelier.pt
Reply-To: procure11@gmail.com
Subject: Urgent Supplies Needed
Attachment: sample quotation.zip (contains "gggggggg.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ISRStealer

zip f7f93e079c0b31b91af8397148831eaaf2d73be934a460959a69e8b064531fe0

(this sample)

  
Dropping
ISRStealer
  
Delivery method
Distributed via e-mail attachment

Comments