MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd39401c01097b075ab3e5ea0e26cac9355bbc197cb15dd003fc1d1f1fc3babe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.Generic


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: fd39401c01097b075ab3e5ea0e26cac9355bbc197cb15dd003fc1d1f1fc3babe
SHA3-384 hash: 1f399e2c8455d417c23481d95bb1d5ebdfbdf1c278853275c0fa46c8aec4c2dc26daafd89a58e029785a9cc4fe16cf66
SHA1 hash: c2de71115182aa3586ae2906ba93a729f1bb7d3c
MD5 hash: f0479d034c115632f971fc38504cb367
humanhash: vermont-sodium-minnesota-charlie
File name:MOT-09800080000.PDF.GZ
Download: download sample
Signature Adware.Generic
File size:516'694 bytes
First seen:2021-02-04 09:43:31 UTC
Last seen:2021-02-11 20:29:32 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:slX5VRhEFg1bfvitvJvV4lwHlFlPqxJ4QprDd73tTKkL:H21jqhoQlbcJ4orZJKkL
TLSH 78B4239658E0C96C71D24E4885623C934075F5E6EAAE4B1E006C70B3278F35E6FB973E
Reporter GovCERT_CH

Intelligence


File Origin
# of uploads :
13
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Bingoml
Status:
Malicious
First seen:
2021-02-04 09:44:16 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Adware.Generic

zip fd39401c01097b075ab3e5ea0e26cac9355bbc197cb15dd003fc1d1f1fc3babe

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments