MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f19c6bf0a94eb0f9ad7675986efc77a9cdf6882c2ff17f6a05337feb0c3071e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2f19c6bf0a94eb0f9ad7675986efc77a9cdf6882c2ff17f6a05337feb0c3071e
SHA3-384 hash: 24390606966faaf3945a995f5d6ef330a77229559419bc948a9b097a20d322896c955354e8d01208bd01982a6c98ef8e
SHA1 hash: d76e0f9fa09d9e7a6811fca7d81238daf15c4645
MD5 hash: 65a288c287b876d89578afeeaeae68fb
humanhash: double-oregon-lake-friend
File name:order confirmation reference no. FXEPS6S081020.cab
Download: download sample
File size:1'533'185 bytes
First seen:2020-10-14 15:55:28 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 24576:QX9wqMEf6pOFadnQ0Euqv8u1/PZ3cOf8rRD3SCUf2z86w+6zjcObkT4Jov+NxjUu:QX9wqMtFtM8Ox3x8rliOd6jZeLyH
TLSH B06533737970C1898D0342FF81D076FAC5EFDF9A9695CE91362641608A2DE0AB9C036F
Reporter abuse_ch
Tags:cab


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: alhijazgroup.net
Sending IP: 80.85.158.19
From: sales <sabu@alhijazgroup.net>
Subject: order confirmation reference no. FX/EPS6/S08/10/20
Attachment: order confirmation reference no. FXEPS6S081020.cab (contains "order confirmation reference no. FXEPS6S081020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Packed.EnigmaProtector
Status:
Malicious
First seen:
2020-10-14 13:08:37 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

cab 2f19c6bf0a94eb0f9ad7675986efc77a9cdf6882c2ff17f6a05337feb0c3071e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments