MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43f2ac6095876000cb6b70ba5696b5c0005dd73db3b9243c598ca64bc39e043b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 43f2ac6095876000cb6b70ba5696b5c0005dd73db3b9243c598ca64bc39e043b
SHA3-384 hash: 16f7adbd71261824a3e368c2f9ad3687f88de67a02605edfa9bc57d2bb534a0b2a6bba542e20277b9e57be22fe923ae5
SHA1 hash: 2d53637ccb46e410998e70242e7dcd1c0fc024fc
MD5 hash: 2ac5661bbad6a73394ef2a0127c8a384
humanhash: avocado-three-orange-harry
File name:inv_amazon9300023399485PDF.img
Download: download sample
Signature RedLineStealer
File size:1'310'720 bytes
First seen:2020-10-22 06:05:19 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:vIGA3xAROZGhuhOPI83dG5BWumf5VBrN8SiyyjK:vIGAGhucZdpuKBp8d8
TLSH 6155BE423144EC96E05F1DB388EFD1306179FD8E8552CA0E3BC67A2A99F7792206774E
Reporter abuse_ch
Tags:img RedLineStealer


Avatar
abuse_ch
Malspam distributing RedLineStealer:

HELO: amazonservice.com
Sending IP: 23.31.247.209
From: Amazon.com<alerts@amazonservice.com>
Subject: Order Confirmation
Attachment: inv_amazon9300023399485PDF.img (contains "inv_amazon9300023399485PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-10-21 19:19:06 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RedLineStealer

img 43f2ac6095876000cb6b70ba5696b5c0005dd73db3b9243c598ca64bc39e043b

(this sample)

  
Dropping
RedLineStealer
  
Delivery method
Distributed via e-mail attachment

Comments