MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9
SHA3-384 hash: 2e01ab7350e44cdb5237a298cfd969b3803be34cb64ae7e00478253cad79774abe5ed85d77c3b35fa65cd64ddbc4782e
SHA1 hash: 4c4724dc6f39e4cafe5436e92a8ae16fc7697b81
MD5 hash: 33179fe87229a021256f88aeea3f0e2b
humanhash: illinois-quiet-three-crazy
File name:Paymentcopy001pdf.rar
Download: download sample
File size:517'815 bytes
First seen:2021-01-06 07:18:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:8SC1LL/m70DAMqrhATe+2mkZpKPqaVV2PcEGiBBkRGC:81tLm72BqQ+ZpYhJpZ
TLSH 0FB423B544DB0A48F4A85ECB253E5DBECA39A4D06943193D9A465FF8BD2301C3B160FB
Reporter abuse_ch
Tags:rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: relay2.ncc.co.za
Sending IP: 102.132.9.26
From: Mellins I Style - Bethlehem <bethlehem@mellins.co.za>
Subject: Payment Advice
Attachment: Paymentcopy001pdf.rar (contains "Paymentcopy001#pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2021-01-06 07:19:05 UTC
AV detection:
9 of 46 (19.57%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

rar 21911e0614781cba5c8ac7b64d8c60b1174fd55c822343ec65892cbd43d309c9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments