MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 336577f0f05a0a2972c318b58022eaa52c66eee65390b1003f18b3345f593d30. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



404Keylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 336577f0f05a0a2972c318b58022eaa52c66eee65390b1003f18b3345f593d30
SHA3-384 hash: 67f8d16b0644ec561fd3f061f4de6c4fbde66d4913550ba8b3393b63a8563508735c62cc8ff78e9091b91777528b818e
SHA1 hash: 36a843a1a4dddbb45f8e5db2f513d1546dba7650
MD5 hash: a8e733998d1f9c3ff0da82028aa28b73
humanhash: hamper-washington-december-papa
File name:COTIZAR PLANOS.zip
Download: download sample
Signature 404Keylogger
File size:697'573 bytes
First seen:2021-02-04 09:42:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:c1s76CmQu3g++cyC8JmMm7lGQPrhTuotmLZHVoZa5CtlmL2fyqXLGeCQNMg7:ceeuuw7cyYMmcQPJjCZSa5CnfadQZ
TLSH EBE4330DD597A2075660D90461FD667CD90B40400F4EB6A25FD0B8EA07AFFCC6ABB1EB
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: wsu0.bnjo.ga
Sending IP: 165.227.133.176
From: COTIZAR <carlos.fuerte@rumi-ingenieros.com>
Subject: RE: Actualización planos - URGENTE
Attachment: COTIZAR PLANOS.zip (contains "cotizar planos.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-04 09:43:24 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

404Keylogger

zip 336577f0f05a0a2972c318b58022eaa52c66eee65390b1003f18b3345f593d30

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments