MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9e9abec8891d71c20d0a071163f7d9a5fda43bda0632a766167931b8124b467. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c9e9abec8891d71c20d0a071163f7d9a5fda43bda0632a766167931b8124b467
SHA3-384 hash: 33c7140fb555be07a4ffff25153aa6c7b593d835aa6f525fe5fe3a6843fa841b6eaafaa2733c88541ae8125610e052e8
SHA1 hash: ad7d01851df97f36b57492ad0863a2b6251baddc
MD5 hash: 954fb9cc5bd43feda82376beeddbcf3a
humanhash: quebec-violet-two-wisconsin
File name:nBOQ__26_Supply_C.r00
Download: download sample
File size:25'374 bytes
First seen:2026-03-31 01:00:30 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 768:elLFHZPmmZT9MRmwOX/02L6uT3g/V3w4f:axZPP1ORx+51T3g/V3wW
TLSH T177B2D0D3BDACA6C9308C995692BDDA93D2130E92D1846CDA5C5C5E24A903772BB38F14
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter FXOLabs
Tags:r00

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
BR BR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:BOQ & Supply Commerical list_MTC Engineering Sdn Bhd.vbs
File size:2'832'127 bytes
SHA256 hash: 2326bf6f34ab2c03f75fa8c176c5e551b5e1986fe39384687a3a92c6a7ae8d74
MD5 hash: 774200b562ca927a3f4d75e3b2d57eaf
MIME type:application/csv
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
rar
First seen:
2026-03-30T22:03:00Z UTC
Last seen:
2026-03-31T12:54:00Z UTC
Hits:
~10
Threat name:
Script-WScript.Trojan.Kepavll
Status:
Malicious
First seen:
2026-03-31 01:01:34 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

r00 c9e9abec8891d71c20d0a071163f7d9a5fda43bda0632a766167931b8124b467

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments