MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9720d70bd7a43597bd67de466fd2144becd27a20124bf193771a181dfd85dc7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ArkeiStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b9720d70bd7a43597bd67de466fd2144becd27a20124bf193771a181dfd85dc7
SHA3-384 hash: 94ae4d383859e4eb2076ea5d3d11587bb67c396bf2a995df2da89d50520058541d6daf444712b8be31e1d78aa40f45fa
SHA1 hash: 3e60da9691a87ecbb74ce7f8ee43abca3e249aae
MD5 hash: 36f0d8113997ea2912669ae867822f36
humanhash: johnny-skylark-lake-xray
File name:request for quotation and new samples 605969785 06984379.gz
Download: download sample
Signature ArkeiStealer
File size:463'745 bytes
First seen:2020-07-20 07:39:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:xOBwVPOMRYGNOVwJEXWwK7wWwYszmGMb5K9KV1v1:46VPOexNFaGGW0zmGs5K9U1v1
TLSH 57A423181DC1BC857EC59A37304A6D9064774E6E7E343CD1B453FA3A2DD2862FC868BA
Reporter abuse_ch
Tags:ArkeiStealer gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: 195.133.196
Sending IP: 195.133.196.9
From: ChimateK Global <z1@voltacapital.org>
Reply-To: info.chimatek@gmail.com
Subject: REQUEST FOR QUOTATION
Attachment: request for quotation and new samples 605969785 06984379.gz (contains "request for quotation and new samples #605969785 06984379.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Qusarrat
Status:
Malicious
First seen:
2020-07-20 07:41:06 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ArkeiStealer

zip b9720d70bd7a43597bd67de466fd2144becd27a20124bf193771a181dfd85dc7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments