🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f9580cce2ac8f7c38acc2ca6ef4872fb99a968c1be76ece7db1b791e6cff346f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f9580cce2ac8f7c38acc2ca6ef4872fb99a968c1be76ece7db1b791e6cff346f
SHA3-384 hash: 9ba73b4c5199456ccee2e1904f9ddfcfbde481740e8ed41e41f9cc1d8d361f537d0c2c95ede4a513bcbc0653ea478268
SHA1 hash: ae8b6b2247f2cfb4e95b6421905a0aeedb9aaec0
MD5 hash: aa2a2f2d6f10267ebbdcab31f2dd9404
humanhash: quebec-twelve-harry-kansas
File name:AWB NOA00060819__DHL_Express_delivery service22032020__Pdf.ace
Download: download sample
File size:25'297 bytes
First seen:2020-04-02 18:42:09 UTC
Last seen:2020-04-04 12:48:33 UTC
File type: ace
MIME type:application/octet-stream
ssdeep 768:2Z94Z3ysdodCXwWTde6qaKO2eFEdtirwgsB:2Z23ysCdCe6yOidtywgA
TLSH 14B2E0687E59E0CDBBA1C640C154AB32896F6FDC83DB520912E77D6693C79EC6018C8F
Reporter jarumlus
Tags:Lokibot

Intelligence


File Origin
# of uploads :
2
# of downloads :
1'024
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-03-31 18:11:51 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
18 of 30 (60.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments