MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c94c3335e7046ab04855871c5d82e1bd739194cfd2228d51cceb3550fdfd81e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6c94c3335e7046ab04855871c5d82e1bd739194cfd2228d51cceb3550fdfd81e
SHA3-384 hash: bd31736e585c5f8dfe62fe687861ef77e074720654255e5c36ff30221d1e1575211f2b1e576b6c1a29960680b3a3bef8
SHA1 hash: e787bbca1226d787c584222c23d483f50523b622
MD5 hash: df4c7f50ba608f190be059053a324ad2
humanhash: snake-magnesium-network-carpet
File name:Documentos de pago.img
Download: download sample
File size:1'245'184 bytes
First seen:2021-01-13 07:27:25 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:fpB4Ik/0iRMbx0V7DML8Rv+vOf4ikNOt/0CL5Glvd99j0ah2/a0XJtb5j7fFHDKx:hB4Ig0qgx0vtHDKXgVn1o4YQKdsP
TLSH F2454855CFD29710D7EC22FE251540622AF5C3B8B2ECEB2CD949B076AF9692801FD1D2
Reporter abuse_ch
Tags:ESP geo img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: iohost05.ioconda.com
Sending IP: 200.76.24.246
From: A&N Forwarding, INC. <facturacion@anforwarding.com>
Subject: Aviso de pago - Ref. Aviso[G1117599144] / Pago prioritario
Attachment: Documentos de pago.img (contains "documentos de pago.PDF____________________.bat")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Androm
Status:
Malicious
First seen:
2021-01-13 06:52:07 UTC
AV detection:
12 of 46 (26.09%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

img 6c94c3335e7046ab04855871c5d82e1bd739194cfd2228d51cceb3550fdfd81e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments