MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a |
|---|---|
| SHA3-384 hash: | 100b019e3235e29f9a887c9c65d5980923615bda3b603f42ad211239523f764fed6f956ec8be918ee9fb25efb13402e9 |
| SHA1 hash: | d469b6f67ca0712d6ef73a45ebe3debe09f44c04 |
| MD5 hash: | f330350fe081b9ae59831e921457ddbc |
| humanhash: | venus-coffee-lion-carbon |
| File name: | PaymentConfirmation2.pdf...exe |
| Download: | download sample |
| File size: | 727'552 bytes |
| First seen: | 2020-10-14 16:23:27 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'853 x AgentTesla, 19'780 x Formbook, 12'304 x SnakeKeylogger) |
| ssdeep | 12288:xo/x8TivVqatQGWOXV+3tltvul7FkSDxCObrI+Z:uzNqat9WGV+VvulGqXvI6 |
| Threatray | 26 similar samples on MalwareBazaar |
| TLSH | 95F48CB95340DD9BDE3823B5D01819F045EABE92E570F2CB3E953CA976F368B0392506 |
| Reporter | |
| Tags: | exe |
abuse_ch
Malspam distributing unidentified malware:HELO: discountfabrics.co.uk
Sending IP: 45.137.22.125
From: info@discountfabrics.co.uk
Reply-To: info@discountfabrics.co.uk
Subject: FACTURA DE PROFORMA
Attachment: PaymentConfirmation2.pdf..z (contains "PaymentConfirmation2.pdf...exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Detection(s):
Result
Verdict:
Malware
Maliciousness:
Behaviour
Sending a UDP request
Creating a window
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2020-10-14 06:47:52 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
1/5
Detection(s):
Suspicious file
Verdict:
unknown
Similar samples:
+ 16 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
657ccf370d9c46343c3dc9cad2cb867db355f5d5752089113fe71320286ffa2c
MD5 hash:
a3cf5440bd3fe296bc8ca51fa2eeee35
SHA1 hash:
05e4ed22fe2b479681894882d3bae70ed235beea
SH256 hash:
01dd844990e0c5fdcea0f88712253aa1ef4750316f0734ab7099306170b5ea2a
MD5 hash:
eb593633270aa19162cf64663df9dd6c
SHA1 hash:
2ec57181471ff10abe9a04239ca3ea86ea4252b9
SH256 hash:
6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a
MD5 hash:
f330350fe081b9ae59831e921457ddbc
SHA1 hash:
d469b6f67ca0712d6ef73a45ebe3debe09f44c04
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
exe 6d3336beda3b924eba9e971f2c109d2a8485fb33b3c018d8dda37df3fdafa71a
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.