🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5649da2bbced4657c855dcb14c39eb45fffce62b3a947975e63812723bcdcc19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RecordBreaker


Vendor detections: 2


Intelligence 2 IOCs 1 YARA File information Comments

SHA256 hash: 5649da2bbced4657c855dcb14c39eb45fffce62b3a947975e63812723bcdcc19
SHA3-384 hash: ae5a8c7392dc852fed31b8450c819edad28fd179628b794cc3b3502eb1c82c9c7f7e2da601f1b58c71084fe5ef8d1853
SHA1 hash: 023fa4d1127c9b4e1df2118bf42804de12d877eb
MD5 hash: f9ae31e86a51f586b9ce160b88d60578
humanhash: pennsylvania-comet-juliet-nitrogen
File name:Telekom Rechnung FEBRUAR 2023 pdf .rar
Download: download sample
Signature RecordBreaker
File size:10'436'706 bytes
First seen:2023-03-06 15:08:23 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 3900
ssdeep 196608:un90HfJ/Cy11GbwC9x0dEj9ObNGgpsPc4SN8KjgI5REa+wfRoItp4049mcP+:U0lN11AwCv0+BCNbpM1KMIXvfR740m/G
TLSH T145B6337486C795748C88833BC2123F3953C6EDE5A523E9678BA217EF45CB4CBCA461B1
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter malkoegler
Tags:pw-3900 Raccoon RaccoonStealer rar recordbreaker


Avatar
malkoegler
https[:]//share-docs[.]clickup[.]com/9004041967/p/h/8caxhqf-201/5006bc417d6ea22

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://51.195.166.206/ https://threatfox.abuse.ch/ioc/1085856/

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
DE DE
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Telekom Rechnung FEBRUAR 2023 pdf .exe
File size:10'819'072 bytes
SHA256 hash: f4232df0afcd172ba07eb6d6abffbb2e149e6221ebaba2da2e0f1e0845600789
MD5 hash: a9f4e5d21dbcb6455928db44bdd058b3
MIME type:application/x-dosexec
Signature RecordBreaker
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Loads dropped DLL
Reads user/profile data of web browsers
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via e-mail link

Comments