MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb525d41fc8c040d775398d851a398ee397b2725a3821218976ff9a6b0c4e5a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bb525d41fc8c040d775398d851a398ee397b2725a3821218976ff9a6b0c4e5a1
SHA3-384 hash: b8328b732da2211f55b38a7b907c42938fb81fe4eb252eb9eaec4eeca96b60c962605c1181cb7261a5094e85c3565407
SHA1 hash: 577a1616b2e7239a3257bd78c0a6011c665ddf61
MD5 hash: f1abfc6aada4a741852202c7e6cd92d0
humanhash: mirror-timing-johnny-nebraska
File name:AWB - Invoice And Shipping Documents.gz
Download: download sample
File size:980'305 bytes
First seen:2021-01-08 19:04:50 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:sveI1Ys96K7dEagKdmRBwAjma5q+O5S1su1Rds9:s2mYsQsBg36SqnS1nRdg
TLSH A92533A6B6C4F70A574C351B0FDA26B03B75FF5434BE166E5AC87D2985C31437088E89
Reporter abuse_ch
Tags:gz HostGator


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gateway23.websitewelcome.com
Sending IP: 192.185.50.107
From: info@good-shepherd-ministries.org
Subject: AWB N0: 3029****6411 ready for pick-up
Attachment: AWB - Invoice And Shipping Documents.gz (contains "AWB - Invoice And Shipping Documents.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
172
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-08 19:05:08 UTC
AV detection:
10 of 46 (21.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz bb525d41fc8c040d775398d851a398ee397b2725a3821218976ff9a6b0c4e5a1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments