MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa02a3fdc9a0f8fad335925a6f45319cf2749c0e0a2405da6277b8fc1236147f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: aa02a3fdc9a0f8fad335925a6f45319cf2749c0e0a2405da6277b8fc1236147f
SHA3-384 hash: 6c8106f96de2eb43176645b0422b03b4054ed736e6141a368f81efc624bb8d41464206810ab0d881c32a013130cda1aa
SHA1 hash: 4f47126bd992346a3faca273f971abaf3643f54e
MD5 hash: ccd82692def1171af493a57b50f65830
humanhash: nitrogen-oven-uncle-california
File name:items_globalsources.rar
Download: download sample
File size:290'607 bytes
First seen:2020-08-06 13:14:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:q5kuy0Va4gZ/pShb4q3EROsluaBKIdFNWifqiXDoOzD51z:syON4XOs1p9tfTXDo0Z
TLSH 1354238196CC438CCAF216E8AE245F1650C7644AB762B6F174CB9DBBE4109379E83DC3
Reporter abuse_ch
Tags:HostGator rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gateway22.websitewelcome.com
Sending IP: 192.185.46.225
From: Acharya Balkrishna <eng@szboxcon.com>
Subject: RE: DQM 4,,8,10 confirmed items
Attachment: items_globalsources.rar (contains "items_globalsources.com")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Downloader.Dofoil
Status:
Malicious
First seen:
2020-08-06 13:16:09 UTC
AV detection:
19 of 47 (40.43%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

rar aa02a3fdc9a0f8fad335925a6f45319cf2749c0e0a2405da6277b8fc1236147f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments