🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 546f8b2f6a3ea4cb7b357238d71b248ec9cbafed3ea540a9efb777f0617b0acd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA 2 File information Comments

SHA256 hash: 546f8b2f6a3ea4cb7b357238d71b248ec9cbafed3ea540a9efb777f0617b0acd
SHA3-384 hash: 06a3b30b65ff0b81a70b05d0fec6873c91b723a40430db1eadb517e67e0102acdbadbaa01df947387b15c87c0502625c
SHA1 hash: e10839b37130e4744d477b2d892d018f96a88ba0
MD5 hash: bf67dad53c76681ab30926a77de66324
humanhash: one-illinois-delta-alanine
File name:SOLAR 26548.pdf
Download: download sample
File size:27'977 bytes
First seen:2024-08-14 19:03:45 UTC
Last seen:2024-08-15 11:39:24 UTC
File type: zip
MIME type:application/zip
ssdeep 768:LoKLbRfTA4XV4C81tFMDQXhCCTAhZygwAkCfUq2oW+MNqn:LoKLbRb340QoIwygFfhWE
TLSH T14DC2E0922DF861EBC652E1B5E7A19E18D86660C13DD40389E0ED12D023F47D70AEEB16
Reporter cocaman
Tags:pdf zip


Avatar
cocaman
Malicious email (T1566.001)
From: ""0901643:ID.M arriott" <Fabian.Suarezp2zkp@krohkpn.southoflacorp.com>" (likely spoofed)
Received: "from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11on2090.outbound.protection.outlook.com [40.107.223.90]) "
Date: "Thu, 15 Aug 2024 11:36:49 +0000"
Subject: "RE: o58p5 Pending - Order Marriott Luxury Pillows 2-Piece Set ID:910421470"
Attachment: "Marriott Luxury Pillows 2-piece set Exclusive Rewards.pdf"

Intelligence


File Origin
# of uploads :
16
# of downloads :
173
Origin country :
CH CH
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:Area_Solicitud_Imagen_Campo_Rubiales.sbx
File size:116 bytes
SHA256 hash: 9cbee5e1135973e8cf6268600b5a609714c0105bfeb2ece21120a8fda6376ed7
MD5 hash: 3ce04f39fd0961f197980b66d0655cbe
MIME type:application/octet-stream
File name:Area_Solicitud_Imagen_Campo_Rubiales.shp
File size:11'740 bytes
SHA256 hash: 6d0da9d1a8f715e11873dbc1246de1fa8b144e5601f65de21f85517c06a9d168
MD5 hash: 47565c3eb3d5b0952b0eef36fb2b6d62
MIME type:application/octet-stream
File name:Area_Solicitud_Imagen_Campo_Rubiales.sbn
File size:132 bytes
SHA256 hash: 29638b66a1d91f0311723dbbf2ccd6fa817dcdc586467c1cd206d68d5e88c6be
MD5 hash: e90859d19d05c6670ce063770c6a7f2d
MIME type:application/octet-stream
File name:Area_Solicitud_Imagen_Campo_Rubiales.shx
File size:108 bytes
SHA256 hash: 7bec60ee573890e6d0148b146a0e6f9ffcfb2facf61b45be4e72e1c25e190e61
MD5 hash: c8dc97d8dae7fc8a12b9d14fad9ab156
MIME type:application/octet-stream
File name:Area_Solicitud_Imagen_Campo_Rubiales.prj
File size:402 bytes
SHA256 hash: 7a167f11059ea6905c4b85992a746ecfed9c4ca9cda51d139c373bf918dbe648
MD5 hash: 9937a1068e68efc1bc4beeb5580cbc8d
MIME type:text/plain
File name:Area_Solicitud_Imagen_Campo_Rubiales.kmz
File size:14'573 bytes
SHA256 hash: 0e3071822caf90b2641b791cf526b0803fb7c9482e369a1471a19b80b75e8a08
MD5 hash: f30aae4d72b20c0d86f76e04fe521896
MIME type:application/zip
File name:Area_Solicitud_Imagen_Campo_Rubiales.dbf
File size:1'720 bytes
SHA256 hash: fc6aad0eab0e8d1f3534721872b0918c8be3bed7369ab19daa7629174489d4e0
MD5 hash: 82888291a1a09d69adbed903bcf4e8d2
MIME type:application/x-dbf
File name:Area_Solicitud_Imagen_Campo_Rubiales.shp.xml
File size:12'727 bytes
SHA256 hash: fddbe5edfaebf7d0aded9724750aa51f1797a8c1620d5208a79987cc84acab65
MD5 hash: d8f4e976dae41ed365ae49f2de9db94c
MIME type:text/xml
File name:Area_Solicitud_Imagen_Campo_Rubiales.cpg
File size:5 bytes
SHA256 hash: 3ad3031f5503a4404af825262ee8232cc04d4ea6683d42c5dd0a2f2a27ac9824
MD5 hash: ae3b3df9970b49b6523e608759bc957d
MIME type:text/plain
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:yara_template

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip 546f8b2f6a3ea4cb7b357238d71b248ec9cbafed3ea540a9efb777f0617b0acd

(this sample)

3ad3031f5503a4404af825262ee8232cc04d4ea6683d42c5dd0a2f2a27ac9824

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SHA256 3ad3031f5503a4404af825262ee8232cc04d4ea6683d42c5dd0a2f2a27ac9824
  
Dropping
SHA256 fddbe5edfaebf7d0aded9724750aa51f1797a8c1620d5208a79987cc84acab65

Comments