MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1779b3dbbc49afed54c2ee6ba762d923c41b3a761cebfb508354fd3f1a2d4561. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 1 Yara Comments

SHA256 hash: 1779b3dbbc49afed54c2ee6ba762d923c41b3a761cebfb508354fd3f1a2d4561
SHA3-384 hash: 69a51a64bd824629680d074c105fad48b919050c9426a4609924579c71b242fce28a1f70e1a62e91e9125c313509b734
SHA1 hash: 44e5922c6dfa0140ee3f2a9ab1a92c846bacf21e
MD5 hash: 6a59329cf028af25ce9629c83ad72744
humanhash: pluto-connecticut-south-apart
File name:Report_N-05002097460.zip
Download: download sample
Signature n/a
File size:481'808 bytes
First seen:2020-06-30 06:27:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ht9psu5VhOvuU242jbuKTGt31VYKweQB+ra7JfNwQz1kKM19giLy84iSAHAl67:P9qChOv8jKtwKweda7Dhkt4iSAHz
TLSH BEA423FDC8A57A4C707F71503F802C4D098DE3DD499A62AA1F7864EBF145B1E21613EA
Reporter @jarumlus

Intelligence


Mail intelligence
Trap location Impact
CH Switzerland Low
Global Medium
# of uploads 1
# of downloads 26
Origin country FR FR
ClamAV SecuriteInfo.com.JS.Obfus-2119.UNOFFICIAL
TwinWave.EvilDoc.DridexBrokenWings.20200508.UNOFFICIAL
TwinWave.EvilDoc.DOCXRSTRGOOD.WSCRIPT.SHELL.200129.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/1779b3dbbc49afed54c2ee6ba762d923c41b3a761cebfb508354fd3f1a2d4561/
ReversingLabs :Status:Malicious
Threat name:Document-Word.Trojan.Rdn
First seen:2020-06-29 12:42:50 UTC
AV detection:14 of 30 (46.67%)
Threat level:   2/5
Spamhaus Hash Blocklist :Suspicious file
VirusTotal:Virustotal results 24.19%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip 1779b3dbbc49afed54c2ee6ba762d923c41b3a761cebfb508354fd3f1a2d4561

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments