MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e10054a5ee7f9c7746d526de88cfcc466f28c2c7c26512b3f21c0bc28e2efd2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2e10054a5ee7f9c7746d526de88cfcc466f28c2c7c26512b3f21c0bc28e2efd2
SHA3-384 hash: 4f6ae5e680dd8cd139d6d38b5136074416b7e21bf5332aea8adf0952cdbef5630dbd7b802eab4664f7362a42f5e86562
SHA1 hash: 205f41feeeaf52ea9ded53d8e86bda3cd7d0192b
MD5 hash: 60918b39c57c2fdf70f29ac0ddc8c55c
humanhash: winner-lion-berlin-muppet
File name:INVOICE.gz
Download: download sample
File size:508'160 bytes
First seen:2021-01-14 20:22:16 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:Vn2NbtWbs8Lo0fuR5yvB+kt058zSRq+duA:ANb8YR5MBjg8J+P
TLSH A8B4233D9DE19E8107B585AB1CB7A34612837F881DAAFB5D8EB101423E047DADCDB523
Reporter abuse_ch
Tags:DHL gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: vps.osmispee.com
Sending IP: 45.85.90.199
From: DHL Express Customer Financial Services<office@osmispee.com>
Subject: Customer Dhl Invoice
Attachment: INVOICE.gz (contains "INVOICE.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2021-01-14 20:23:07 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz 2e10054a5ee7f9c7746d526de88cfcc466f28c2c7c26512b3f21c0bc28e2efd2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments