MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 526a260f4984baa65166b315987c659e04b175e870138180653924d585279eaa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 526a260f4984baa65166b315987c659e04b175e870138180653924d585279eaa
SHA3-384 hash: 12222333cabe4982860ad120409410765b8000f7ed80814f00c357b6b99ef54e377053ee01b1a5d5edae6b6efec009b5
SHA1 hash: 1018755169608bab1517b8119d723fd4b3c1719a
MD5 hash: fc4609af93f6ccc58dd28fc83b60143e
humanhash: saturn-missouri-florida-eight
File name:New purchase order 50,689.rar
Download: download sample
File size:975'393 bytes
First seen:2020-10-24 06:37:04 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:IL40FbWL/J2NRIingsr9+wR+maQjKsvtJuddJ:IVKLB2wsr9+w+m1jlGLJ
TLSH F72533B5C6E5E480C5892D99AC244A046A03D27F2FDBC0BC456777A049F5E2AF4BFC27
Reporter abuse_ch
Tags:GMX rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mout.gmx.com
Sending IP: 74.208.4.201
From: al-safi <al-safiscs@chef.net>
Subject: Re: Purchase Order Details
Attachment: New purchase order 50,689.rar (contains "New purchase order 50,689$.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-23 19:45:22 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

rar 526a260f4984baa65166b315987c659e04b175e870138180653924d585279eaa

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments