MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16041ab958ce23e9dda80466f94fccd8942c76f518310b3de187cd7ccc686449. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 16041ab958ce23e9dda80466f94fccd8942c76f518310b3de187cd7ccc686449
SHA3-384 hash: 864deeb175697cca7b6a696d43e5e62d35cdba74b29bad28ebc8a048a534a8fa3c6f40e9b8dcd041307ae8e75d1a033a
SHA1 hash: 60c9696009e579ab1a12071ef168b27d2e90d5be
MD5 hash: a7ef4567097bef914b83ae809b76ecf1
humanhash: victor-quebec-ceiling-hot
File name:cotizacin 345355.PDF.gz
Download: download sample
File size:971'869 bytes
First seen:2020-07-29 13:09:25 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:VNzc3zSmD+lU8kMMNSLRb0vjpN8sKopKL6f:VNcDSmy2MMstbMjpNNKdw
TLSH 5125333291FB9DE42B806AD196D9B4FAAB37D4DE2934350C701337A10BF974B7164AC8
Reporter abuse_ch
Tags:gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gasteev.com
Sending IP: 37.49.224.121
From: Norma Hernandez Perez <info@gasteev.com>
Subject: LISTAS DE PRECIOS Y CARTAS
Attachment: cotizacin 345355.PDF.gz (contains "cotizacin 345355.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 13:11:04 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz 16041ab958ce23e9dda80466f94fccd8942c76f518310b3de187cd7ccc686449

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments