MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9 |
|---|---|
| SHA3-384 hash: | 2e01ab7350e44cdb5237a298cfd969b3803be34cb64ae7e00478253cad79774abe5ed85d77c3b35fa65cd64ddbc4782e |
| SHA1 hash: | 4c4724dc6f39e4cafe5436e92a8ae16fc7697b81 |
| MD5 hash: | 33179fe87229a021256f88aeea3f0e2b |
| humanhash: | illinois-quiet-three-crazy |
| File name: | Paymentcopy001pdf.rar |
| Download: | download sample |
| File size: | 517'815 bytes |
| First seen: | 2021-01-06 07:18:51 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:8SC1LL/m70DAMqrhATe+2mkZpKPqaVV2PcEGiBBkRGC:81tLm72BqQ+ZpYhJpZ |
| TLSH | 0FB423B544DB0A48F4A85ECB253E5DBECA39A4D06943193D9A465FF8BD2301C3B160FB |
| Reporter | |
| Tags: | rar |
abuse_ch
Malspam distributing unidentified malware:HELO: relay2.ncc.co.za
Sending IP: 102.132.9.26
From: Mellins I Style - Bethlehem <bethlehem@mellins.co.za>
Subject: Payment Advice
Attachment: Paymentcopy001pdf.rar (contains "Paymentcopy001#pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2021-01-06 07:19:05 UTC
AV detection:
9 of 46 (19.57%)
Threat level:
1/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
rar 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.