MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd3839c5c9d4c6aad7dde1f4d338e58ea1e58b4810680375f7edebe62858031b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fd3839c5c9d4c6aad7dde1f4d338e58ea1e58b4810680375f7edebe62858031b
SHA3-384 hash: 02f252fb33e7ee94f0451be27f3a53be864a8b88265c84d00396db9600ee0467893f782396d69c224c1f043acae2d7b2
SHA1 hash: 9eaabd144e033f36dc056b7adfaf9f682cfaf20a
MD5 hash: 12674c604ff5b3f9017482724bcf516e
humanhash: fix-november-michigan-magazine
File name:invoice copy.pdf.z
Download: download sample
File size:504'040 bytes
First seen:2020-08-18 11:08:37 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:MUkwl0N+eww1PPeGGeQlplillSNL0AWz+NpyRUVH:Mkl0oez+veQlplTZI+DH
TLSH 1CB423D95FC98A33299BC44F3BE5F0A7226B8EC41629AA351B52CD32700C33D2B5765C
Reporter abuse_ch
Tags:z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: alkuhaimi.com
Sending IP: 37.48.85.226
From: Financial Manager <rud-division@alkuhaimi.com>
Subject: FW: 回复: paid invoice
Attachment: invoice copy.pdf.z (contains "invoice copy.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-18 11:10:10 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

z fd3839c5c9d4c6aad7dde1f4d338e58ea1e58b4810680375f7edebe62858031b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments