MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c33b97b9f7a2d8ba9ec9e4b071b55267a38330e94b1fdda971bbf7d0586e02c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3c33b97b9f7a2d8ba9ec9e4b071b55267a38330e94b1fdda971bbf7d0586e02c
SHA3-384 hash: 3c478122cd91a7adfa1832d4b280c94d127849689b21393789cf65805a91bd9d1dad867007efcfa0d25e9b3ceed749eb
SHA1 hash: 8dc4b556e0328280a68cacc7585b636634fc3600
MD5 hash: 2f3b9d69705cb568cd2f0c45318b4f43
humanhash: missouri-zulu-louisiana-alabama
File name:DHL_document1102202068090891.zip
Download: download sample
Signature NanoCore
File size:697'726 bytes
First seen:2021-03-04 07:27:54 UTC
Last seen:2021-03-05 13:44:40 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:t/lJckejYcGCIRct3NGUwmkmBnYpmzahwfGee36bWaoKgOWPF4RNEWmWhNPO:h6YHN2QmiAg36bfE9KNfy
TLSH 74E423A59D42BD6B17CDB4CE4490F8631CE848822F453A58BFF53216868644FFA473AF
Reporter lowmal3

Intelligence


File Origin
# of uploads :
3
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-03-04 03:23:00 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 3c33b97b9f7a2d8ba9ec9e4b071b55267a38330e94b1fdda971bbf7d0586e02c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments