MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a26bad6d27acc175eaf401a27458708ecb8950a4c6331a479a6b38bd23b15f20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
HawkEye
Vendor detections: 4
| SHA256 hash: | a26bad6d27acc175eaf401a27458708ecb8950a4c6331a479a6b38bd23b15f20 |
|---|---|
| SHA3-384 hash: | 8c551a682cab7399d9271c661d77be788c99833d1537cf9990b9bec1c6da03cad9782fc30f8e0b032a75902c8d832b96 |
| SHA1 hash: | 5907561563935a008bd8f5784918fdb5a58551ab |
| MD5 hash: | ba631067bffb779efc72bff83f84ea4a |
| humanhash: | early-kansas-california-network |
| File name: | CF.zip |
| Download: | download sample |
| Signature | HawkEye |
| File size: | 788'639 bytes |
| First seen: | 2020-10-11 16:40:37 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 24576:pvMCSOpnc6BM4nMvENT7ZVk8cyfq4vrcCBhVFbKPFvN7b:lRc6BsEFZvDq4vvBhVFbK5F |
| TLSH | F4F4338BB0FA93D7412D57E20C52EAF9E11514A155FE90EF3CB63221B528B32D1BF528 |
| Reporter | |
| Tags: | HawkEye zip |
abuse_ch
Malspam distributing unidentified malware:HELO: altesoman.com
Sending IP: 107.173.40.220
From: For Al - Alalan Trading LLC (ALTES - LLC) <mangesh@altesoman.com>
Subject: RE: C & F price to Oman for below – as per your scope of supply
Attachment: CF.zip (contains "C&F.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Worm.Ramnit
Status:
Malicious
First seen:
2020-10-11 11:53:55 UTC
AV detection:
37 of 48 (77.08%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.