MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f10ba8b06a3910c58655c9a7e5553b461c1e88d42e882abe42657596cf8795d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0f10ba8b06a3910c58655c9a7e5553b461c1e88d42e882abe42657596cf8795d
SHA3-384 hash: 99b087cfeb87bff779fdb292ef4adb4789931b6eb0c4af60c9039c7010bdde0ac28099b5189b9a1b9f86bc518b95bc73
SHA1 hash: f3da4ec512f1fd959d12b8113a629456cb5b4fe9
MD5 hash: e4d686115c2e0c1d0d4b3f0007a5dc8d
humanhash: black-earth-fish-london
File name:sino_project_approved_products_5109735005181_list.rar
Download: download sample
Signature HawkEye
File size:438'063 bytes
First seen:2021-01-08 08:15:58 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:+B22VIh3oIqzOdaMAg2XyV1CJp8CmwfZZuvc8yWR:+6BB70pk0ZMvcU
TLSH 2A94235B7EC7AAF09B44FA7A3D04B119E6E070DCD14CFD3449065ACB62E82A4BCA5173
Reporter abuse_ch
Tags:geo ITA rar UniCredit


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: unicreditgroup-italy.eu
Sending IP: 46.183.221.10
From: UniCredit S.p.A.<info@unicreditgroup-italy.eu>
Subject: Re: copia di trasferimento
Attachment: sino_project_approved_products_5109735005181_list.rar (contains "sino project approved products 5109735005181 list.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
130
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-08 08:16:09 UTC
AV detection:
22 of 46 (47.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

rar 0f10ba8b06a3910c58655c9a7e5553b461c1e88d42e882abe42657596cf8795d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments