MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fb13a158aff3d258b8f62fe211fabeed03f0763b2acadbccad9e8e39969ea00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1fb13a158aff3d258b8f62fe211fabeed03f0763b2acadbccad9e8e39969ea00
SHA3-384 hash: 0e088f0acdffc204aaaba2ad6afe62aec66a3b04e465e3223591ef025fb5e472f6ade69c49e41219c1a0b061ed64d0d8
SHA1 hash: 56a8d4f7009caf32c9e28f3df945a7826315254c
MD5 hash: e770385f9a743ad4098f510166699305
humanhash: vermont-twenty-mars-alanine
File name:ministry.cab
Download: download sample
File size:2'142'304 bytes
First seen:2021-09-02 03:52:30 UTC
Last seen:2021-09-10 06:00:41 UTC
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 49152:nq2pBROC82lyzqn6lqOXQ7Wzwyyv7Fo6LnTqPuDyJ4w:BrPMzwnFo6HxDyuw
TLSH T1FCA56C15B7A800E5CA76C27C8953891BD7F2B82507B09BDF17695ABE0F237D11A3E708
Reporter JAMESWT_WT
Tags:cab CVE 2021 40444 CVE-2021-40444 hidusi_com related

Intelligence


File Origin
# of uploads :
3
# of downloads :
1'040
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win64.Trojan.Ursnif
Status:
Malicious
First seen:
2021-09-02 03:53:06 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
8 of 45 (17.78%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments