MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f2731b2f8298529bb14b01b6c3199035af4bc05200dcb4baa299d33fc202d46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0f2731b2f8298529bb14b01b6c3199035af4bc05200dcb4baa299d33fc202d46
SHA3-384 hash: ee265a0e15e7a8edeaa0bfcdd730c96975b656a56f6e6ead8ca8fdd7317c754f011c8fabdc6d27f94dcdb5bc9cc4b165
SHA1 hash: a09a1749747ee9878b2e599fa9e3d17da94f9384
MD5 hash: 530910fd12b4b8a70c8a774bee56f634
humanhash: summer-seventeen-robert-nevada
File name:BLTAX.xlsm.xxe
Download: download sample
File size:493'568 bytes
First seen:2020-08-25 10:16:46 UTC
Last seen:Never
File type:
MIME type:application/x-iso9660-image
ssdeep 6144:J+8iBvmJCFxZ0LuuOvKMxyLXUIfBYq5WtEdoXgzKokYR+JvkH0G4A0RYwBeYGq+C:JwBJZ2upi2yLvYYAEdXbB4A0sYGqD
TLSH 81A4DF88BB51F64ECB5A8D7648612D108661A4B7071BF647BDCF12FD570F3BA8E012E2
Reporter abuse_ch
Tags:Xxe


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: "Alphalog/TPE-Export" <export@alphatpe.com.tw>
Subject: BL/TAX
Attachment: BLTAX.xlsm.xxe (contains "BLTAX.xlsm.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-25 10:18:08 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

0f2731b2f8298529bb14b01b6c3199035af4bc05200dcb4baa299d33fc202d46

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments