MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 640bb73cc2576884be85bb0018497e77fa684493fdda95a711f5936bab002b18. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 640bb73cc2576884be85bb0018497e77fa684493fdda95a711f5936bab002b18
SHA3-384 hash: 3341e38650a3b3978113a2054da265bae39c3825cd30339f0c75b74df5cd14568b4ec9680e9b24d292e8ec28a5e6d619
SHA1 hash: 3a31d2230d81d5f2b3db535f4c95d6023b8f3490
MD5 hash: b1db8c0feda71e7525b2fbe214243ec7
humanhash: nitrogen-table-friend-mars
File name:FedExs AWB5305323204643.iso
Download: download sample
Signature NanoCore
File size:83'968 bytes
First seen:2021-02-26 06:54:23 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 384:lq0eRDypgW51V3I22IGFrtmIbQ+TVUkuqphV:lklyp7V72aIbnTYQh
TLSH 20832A072EA7181DD49A863C58A3961DAA33B3C2D5B0C62B30EDB144CBCF7511A6DF79
Reporter abuse_ch
Tags:FedEx iso NanoCore


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: FedEx <track@fedex.com>
Subject: FedEx's AWB#5305323204643 - Information is required
Attachment: FedExs AWB5305323204643.iso (contains "FedEx's AWB#5305323204643.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-26 06:55:08 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

iso 640bb73cc2576884be85bb0018497e77fa684493fdda95a711f5936bab002b18

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments