MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 15c4436deb5fc30241abaa1b024170bff09055a6a32cf34e5713530bfcc7d2ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Neurevt


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 15c4436deb5fc30241abaa1b024170bff09055a6a32cf34e5713530bfcc7d2ba
SHA3-384 hash: fea50ebafd64ca873f2d08a263276cc9212bb9239bd33c714cdbaa8913bf9b7af1531609e9d0a042e697428bca3fdb0f
SHA1 hash: 30cca53069a91dc108f39f66e5d546c60a7c8570
MD5 hash: e2e7426aba2725a5f2d735810d9ba6e5
humanhash: mike-sweet-october-freddie
File name:Customer Complaint letter NCC166289001.PDF.gz
Download: download sample
Signature Neurevt
File size:278'456 bytes
First seen:2020-08-04 11:20:49 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:NUxPpeqPgWaVTAnxZOlfZdZEPxEC53+wjlix7Z0:ujcI/sxv90
TLSH C74423811C18AD2C4F1D19D5CFE168BB5B9E83D39AFC856463835FA9403AC44DB6ECAC
Reporter abuse_ch
Tags:gz Neurevt


Avatar
abuse_ch
Malspam distributing Neurevt:

HELO: host.qualifairs.com
Sending IP: 85.25.130.41
From: complaint@thencc.org.za
Subject: Customer Complaint letter // NCC166289001
Attachment: Customer Complaint letter NCC166289001.PDF.gz (contains "Customer Complaint letter NCC166289001.PDF.exe")

Neurevt C2:
http://winqits.com/~zadmin/lk/dm/logout.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Neurevt
Status:
Malicious
First seen:
2020-08-04 11:22:11 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Neurevt

gz 15c4436deb5fc30241abaa1b024170bff09055a6a32cf34e5713530bfcc7d2ba

(this sample)

  
Dropping
Neurevt
  
Delivery method
Distributed via e-mail attachment

Comments