MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d52957a263026ffd5726c3cb427236b51fd220a2ea256be01fd198861912e7ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d52957a263026ffd5726c3cb427236b51fd220a2ea256be01fd198861912e7ba
SHA3-384 hash: 0c223963b22653f0fbb4932f54b15a9cbd5699083538b31e98876e0b7a66e144d991a3485a563d89c50a15761beb97fe
SHA1 hash: 1b8b8541ec666fb705b02884750097c8f94031a8
MD5 hash: ec4967df33a209b58ea72b9b3f68e010
humanhash: wyoming-skylark-asparagus-massachusetts
File name:RFQ FOR INQUIRY N-A00573P -Q39648M.PDF.img
Download: download sample
File size:1'245'184 bytes
First seen:2020-10-08 17:40:09 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:FbBgVNqbhwiaGsUhEt6Z5aV+NlxbBhIscJP:F9ugwiaGsEl55N3dhmJP
TLSH CF45E0261794CA66C17E0BB9C47591F043F49E02DA03D61FBDF87CEB3BB2BA14926146
Reporter abuse_ch
Tags:img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: binarbaid.com
Sending IP: 37.48.85.204
From: Mohammad Monawwar Alam (PURCHASE OFFICER) <purchase@binarbaid.com>
Subject: RFQ FOR INQUIRY N#-A00573P -Q39648M
Attachment: RFQ FOR INQUIRY N-A00573P -Q39648M.PDF.img (contains "xSdH9ejh8TOaUeX.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-08 14:16:34 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

img d52957a263026ffd5726c3cb427236b51fd220a2ea256be01fd198861912e7ba

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments