MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80616b96b75786c8f2d11eb715795f82554d29e8c56eede8526d2107dabb8ad6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TaurusStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 80616b96b75786c8f2d11eb715795f82554d29e8c56eede8526d2107dabb8ad6
SHA3-384 hash: 88ce9d6f7d3580618d7b289b63f7f0896fdb610f2ced6448bdb8bf64ace11f1c5d281f80ca78213030c38b2546a410d5
SHA1 hash: dfc44dec88197f16ee89deee1532b0496d15f05d
MD5 hash: 77c3a27813fd93ebb201d65ea4dffa69
humanhash: potato-eight-lemon-ceiling
File name:DHL Tracking info_AWB NO.cab
Download: download sample
Signature TaurusStealer
File size:215'349 bytes
First seen:2021-03-01 07:26:24 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:eNLkprgSmqkeZ4T3MEmoTSMROfsJ1ED5ZoUSmeDLDUiZ3bdd:eKprRDl6SQOfG1S5ZrStL9tbdd
TLSH FE2423CF0F8DF9E3B8585F872116F848F5078C24706B1AB6356E24875BA695F4D102E7
Reporter abuse_ch
Tags:cab


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mx.abb0t.com
Sending IP: 142.93.249.162
From: Susan waya <dxgfhyt5676uyfjh@abb0t.com>
Subject: Re: PO#451093PO#1595_INVOICE#Request Invoice for Payment
Attachment: DHL Tracking info_AWB NO.cab (contains "PO# PO2021020371N.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2021-03-01 01:55:00 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TaurusStealer

rar 80616b96b75786c8f2d11eb715795f82554d29e8c56eede8526d2107dabb8ad6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments