MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb7c4b46e4e2cb8a1d2c5cce88c2bd623e2241777e3a4bd9c76c9ab3d25e695b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adwind


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cb7c4b46e4e2cb8a1d2c5cce88c2bd623e2241777e3a4bd9c76c9ab3d25e695b
SHA3-384 hash: 819178b8ca3d4707ef810fae42e83d475e8bfec63d77702abaa827e1f7d34631d22341b44a176945c50385e1a345b0f0
SHA1 hash: 6c6c58e5b5224685dfcfa5f43c29881e8f0f1969
MD5 hash: 423f0b413c7c46c9405667ce129bd6c8
humanhash: yellow-early-yankee-eighteen
File name:Shipping Documents.jar
Download: download sample
Signature Adwind
File size:408'136 bytes
First seen:2020-06-17 11:41:47 UTC
Last seen:Never
File type:Java file jar
MIME type:application/java-archive
ssdeep 12288:gkmsbz+3VkCSV3p+tJ82lKEHUkB51DDQpj:gkx+3VkCep+tu2lxHzKpj
TLSH F294228ACCCA4164E51387F48593F277379C5007742B60F6DAEDC16E9CB98EBAC958C8
Reporter abuse_ch
Tags:Adwind jar RAT


Avatar
abuse_ch
Malspam distributing Adwind:

HELO: mta04.svc.cra.dublin.eircom.net
Sending IP: 159.134.118.171
From: Chung Do <mckennabrian@eircom.net>
Subject: Re: INCORRECT SHIPPING DOC
Attachment: Shipping Documents.jar

Intelligence


File Origin
# of uploads :
1
# of downloads :
165
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Threat name:
ByteCode-JAVA.Trojan.AdWind
Status:
Malicious
First seen:
2020-06-17 15:24:29 UTC
AV detection:
17 of 47 (36.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
persistence
Behaviour
Views/modifies file attributes
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Drops file in System32 directory
Adds Run entry to start application
Drops desktop.ini file(s)
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Adwind

Java file jar cb7c4b46e4e2cb8a1d2c5cce88c2bd623e2241777e3a4bd9c76c9ab3d25e695b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments