MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc3c7b9eff6355ddf465fefdace339a7964d797b62a83fc764d0b3e892770a04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



404Keylogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: fc3c7b9eff6355ddf465fefdace339a7964d797b62a83fc764d0b3e892770a04
SHA3-384 hash: b78ef0370dc135757df423276349f1dba8fcc27916c9809b43163b81ccee32701ce8a42a5c2ad57a85a639a127c6ba61
SHA1 hash: 6b5efc0caeaaed35fb346e3330dc3f1f24a87c47
MD5 hash: a5d2f50717792c4ac424c8bd722e2aa0
humanhash: delaware-fifteen-venus-alpha
File name:OC.arj
Download: download sample
Signature 404Keylogger
File size:287'235 bytes
First seen:2020-05-27 06:43:40 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:jYeJk8JjtNXrs3qBBWAuslJLLc3GR7CLtW2lsBr9cLP8Xiz:jYeJk8NTHBzFJX9BCBW9vs
TLSH 5654239FDF0662C937219B93481126149C97BAC4D86F5D7B242199F3278BCFBC308E68
Reporter abuse_ch
Tags:404Keylogger arj


Avatar
abuse_ch
Malspam distributing 404Keylogger:

HELO: mail.cidelsa.com
Sending IP: 190.223.44.24
From: Fernando Bazan <fbazan@cidelsa.com>
Subject: Re: confirmación del pedido
Attachment: OC.arj (contains "oc.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 07:19:40 UTC
File Type:
Binary (Archive)
Extracted files:
265
AV detection:
16 of 30 (53.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

404Keylogger

arj fc3c7b9eff6355ddf465fefdace339a7964d797b62a83fc764d0b3e892770a04

(this sample)

  
Dropping
404Keylogger
  
Delivery method
Distributed via e-mail attachment

Comments