MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53dab0fb12afefb47f342c4e76da063251be9e45555a1b7d6fb436a1e7c3b88e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Neurevt


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 53dab0fb12afefb47f342c4e76da063251be9e45555a1b7d6fb436a1e7c3b88e
SHA3-384 hash: 1febce21858a3b00fcc3b774f6fc76d94d7e772982bab8f44310aabd0ae556e30fe50c40409b22495ff83b109f46c9fa
SHA1 hash: 2fa43d3a4af4e477113367e50253b6b8d6456f64
MD5 hash: 73cd29e8619a44fe142331c93d8f4dea
humanhash: ceiling-pluto-high-hot
File name:Purchase Order 480211- CVE8112.PDF.gz
Download: download sample
Signature Neurevt
File size:278'035 bytes
First seen:2020-08-05 12:09:54 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:vcjnxvoVKDjf2WuaB5iNDPzhmQeHEL8TEIgeYRUTUNDg:kbxwCRuND9H52fFsMUg
TLSH D2442371B2888250B2D2A20C466D3DDF9ABF4BB9908787E7AD454437A14C3F1F5AF4D8
Reporter abuse_ch
Tags:gz Neurevt


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: host.qualifairs.com
Sending IP: 85.25.130.41
From: buyer@ffs.co.za
Subject: Purchase Order : 480211- CVE8112
Attachment: Purchase Order 480211- CVE8112.PDF.gz (contains "Purchase Order 480211- CVE8112.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-08-05 12:11:14 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Neurevt

gz 53dab0fb12afefb47f342c4e76da063251be9e45555a1b7d6fb436a1e7c3b88e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments