MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e52667e9ac303fa0be2408ed7bd333c8990f9f98331db17b436f7f4d3f5c79b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e52667e9ac303fa0be2408ed7bd333c8990f9f98331db17b436f7f4d3f5c79b9
SHA3-384 hash: 3d10aa1f46f25628129ca43e991b93206b1c6ab070c37f309e50607dec1caca75f9e74be68be243b958e3c3f9f821903
SHA1 hash: ccac88f9583c849786c46392e989ad8017f818a4
MD5 hash: 898ae4d27eee5962d1f1e604301b6b0d
humanhash: foxtrot-connecticut-lake-rugby
File name:Faktur yang belum diselesaikan_pdf.gz
Download: download sample
File size:1'695'187 bytes
First seen:2020-08-28 06:10:20 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 49152:EQSjZ/aNaylP/sRwiOvVr6mQUKd7S5dz7m:vqpMPkO92BUKd+7z7m
TLSH 7F75331AAB0730F211EA1D7B129BC5391691FB54C8E73B4FC1E6E38A2E7555F0C84D8A
Reporter abuse_ch
Tags:geo gz IDN


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.upp.co.id
Sending IP: 45.126.133.67
From: Account DPT. JKT <salesmerak3@upp.co.id>
Subject: RE: Outstanding Invoices Aug 2020
Attachment: Faktur yang belum diselesaikan_pdf.gz (contains "Faktur yang belum diselesaikan_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-28 06:12:05 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz e52667e9ac303fa0be2408ed7bd333c8990f9f98331db17b436f7f4d3f5c79b9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments