MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1114398558b8115ab84eea605c7b3de9ee1808118b589d7d14e88e3513533df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c1114398558b8115ab84eea605c7b3de9ee1808118b589d7d14e88e3513533df
SHA3-384 hash: f342dc5a15ced616500e6852c9d1aa089758eb1e0cbca75734b33fa0c930c4a514d675365eb00e87bdb86842fc4f0d84
SHA1 hash: 563ccbf3ba0cd752f20a5ef92be5e4aa400d9e8c
MD5 hash: 8f93d2687bb4a415cf10a153868fa885
humanhash: failed-six-mississippi-london
File name:access.zip
Download: download sample
File size:266'674 bytes
First seen:2022-04-14 12:13:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:xNR7LHGwvfjZMQGO2D/UlHyS8IcwbFPesLyPqDzHAUZEuDiY1rp3:xNR76wHdM+UQj7cwlzca7EuOQ3
TLSH T10B44E03BD2094A8CF9D79B3C339EAB21BE55914B1E23B93B07242255ED85DDC2E8F150
TrID 58.3% (.MAFF) Mozilla Archive Format (gen) (7000/1/1)
33.3% (.ZIP) ZIP compressed archive (4000/1)
8.3% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:bancacaixa zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
HTML File - Malicious
Payload URLs
URL
File name
https://cdn.jsdelivr.net/npm/bootstrap
HTML File
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2022-04-02 12:25:47 UTC
File Type:
Binary (Archive)
Extracted files:
123
AV detection:
5 of 42 (11.90%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments