MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f84bea2aa311304b341da66a0b0491f537ecd30c2d7298326686b0ffc9a64435. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ArkeiStealer


Vendor detections: 1


Intelligence 1 IOCs YARA File information Comments 1

SHA256 hash: f84bea2aa311304b341da66a0b0491f537ecd30c2d7298326686b0ffc9a64435
SHA3-384 hash: 79bf3bd21785ef03adcc688b5cd4c4bd2adb0fa1217a4f234cebbaef4c7475e9cac721c643b9428de4b0e9cc05486bfe
SHA1 hash: ab1ea1a9adc7c4016100d5c0c0fa82f013f7cc5c
MD5 hash: 2827f97b0db919c3c6f3c64953ccc4c8
humanhash: robert-missouri-washington-pluto
File name:PASSWORD_IS_324325____ScreenHunter-Pr.zip
Download: download sample
Signature ArkeiStealer
File size:16'427'656 bytes
First seen:2021-12-13 12:47:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:BktQNlv+Mt2K1nNfcMiHXooR5lu3bjMkfDd0Fn+szA7Ytp:atY7PniX3PR5lu3PLZ013Ltp
TLSH T199F6335D4D602F038F81A5FB8BED9051C3C9735E52D2A28F5600ADCA9EF8C6B7D44B98
Reporter iam_py_test
Tags:zip


Avatar
iam_py_test
Password-protected zip. The password is 324325

Intelligence


File Origin
# of uploads :
1
# of downloads :
291
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ArkeiStealer

zip f84bea2aa311304b341da66a0b0491f537ecd30c2d7298326686b0ffc9a64435

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
iam-py-test commented on 2021-12-13 13:59:36 UTC

Contains https://bazaar.abuse.ch/sample/6d7553b09093dc8ff76acdb351b4cef88aebaa05ee58c1ecab5339d03c68a10a/