MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb29038762ba30a0daef186e9bd77495d49c4316ea43cbf81b7903234d0f1098. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Bancteian


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cb29038762ba30a0daef186e9bd77495d49c4316ea43cbf81b7903234d0f1098
SHA3-384 hash: a9275104e5600599062a32be01cebd8c13b8ff4ba7ff47b26226d905ae8f50b5d32fd31789c7db3a7c71594dda8f49ac
SHA1 hash: 59c948dd2ef91039fba38008f7e009985daf849f
MD5 hash: 98ef8fc948c36825e0fde2640a0056fe
humanhash: cup-video-may-mexico
File name:SOA of AUGUST 2020.rar
Download: download sample
Signature Bancteian
File size:1'898'563 bytes
First seen:2020-11-06 07:24:54 UTC
Last seen:2020-11-09 06:24:57 UTC
File type: rar
MIME type:application/x-rar
ssdeep 49152:ot1e8jC+v0QxFyPszQwz7lg3cpJmxlykgZidaW/6Dl5MDNqC:4j0Q9zQyp4xEW/6Dl5MpqC
TLSH 16953351FD87B84EE291E9F80B16C746B9ECB958DDDC396CC9201E94B0347205F8E89E
Reporter cocaman
Tags:Bancteian rar


Avatar
cocaman
Malicious email (T1566.001)
From: ""Godwin Joe"<accounts@lom-logistics.com>" (likely spoofed)
Received: "from lom-logistics.com (unknown [103.99.1.140]) "
Date: "05 Nov 2020 22:04:04 -0800"
Subject: "SOA ON September 2020"
Attachment: "SOA of AUGUST 2020.rar"

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Bancteian
Status:
Malicious
First seen:
2020-11-06 07:26:06 UTC
File Type:
Binary (Archive)
Extracted files:
66
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Bancteian

rar cb29038762ba30a0daef186e9bd77495d49c4316ea43cbf81b7903234d0f1098

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Bancteian

Comments