MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a
SHA3-384 hash: 100b019e3235e29f9a887c9c65d5980923615bda3b603f42ad211239523f764fed6f956ec8be918ee9fb25efb13402e9
SHA1 hash: d469b6f67ca0712d6ef73a45ebe3debe09f44c04
MD5 hash: f330350fe081b9ae59831e921457ddbc
humanhash: venus-coffee-lion-carbon
File name:PaymentConfirmation2.pdf...exe
Download: download sample
File size:727'552 bytes
First seen:2020-10-14 16:23:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'853 x AgentTesla, 19'780 x Formbook, 12'304 x SnakeKeylogger)
ssdeep 12288:xo/x8TivVqatQGWOXV+3tltvul7FkSDxCObrI+Z:uzNqat9WGV+VvulGqXvI6
Threatray 26 similar samples on MalwareBazaar
TLSH 95F48CB95340DD9BDE3823B5D01819F045EABE92E570F2CB3E953CA976F368B0392506
Reporter abuse_ch
Tags:exe


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: discountfabrics.co.uk
Sending IP: 45.137.22.125
From: info@discountfabrics.co.uk
Reply-To: info@discountfabrics.co.uk
Subject: FACTURA DE PROFORMA
Attachment: PaymentConfirmation2.pdf..z (contains "PaymentConfirmation2.pdf...exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2020-10-14 06:47:52 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
657ccf370d9c46343c3dc9cad2cb867db355f5d5752089113fe71320286ffa2c
MD5 hash:
a3cf5440bd3fe296bc8ca51fa2eeee35
SHA1 hash:
05e4ed22fe2b479681894882d3bae70ed235beea
SH256 hash:
01dd844990e0c5fdcea0f88712253aa1ef4750316f0734ab7099306170b5ea2a
MD5 hash:
eb593633270aa19162cf64663df9dd6c
SHA1 hash:
2ec57181471ff10abe9a04239ca3ea86ea4252b9
SH256 hash:
6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a
MD5 hash:
f330350fe081b9ae59831e921457ddbc
SHA1 hash:
d469b6f67ca0712d6ef73a45ebe3debe09f44c04
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Executable exe 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments