MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 171b30ee0e7bc1041ab080338ade87eb5b1db21b2764a5e0c65fddd88fdb6555. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 171b30ee0e7bc1041ab080338ade87eb5b1db21b2764a5e0c65fddd88fdb6555
SHA3-384 hash: e174ecd8188d35142da744d309a542c84cf524cfeac558a8dc64209b6f1d61982ab07c519a19fdbffeafd635a8a66915
SHA1 hash: fe258caae239d42431a57a18d973d094ee424cf5
MD5 hash: cf264dfefbadf04622f727e2b31b8ab1
humanhash: illinois-carolina-utah-wisconsin
File name:Orden de Compra lista.DWG.gz
Download: download sample
File size:943'463 bytes
First seen:2020-10-15 11:24:04 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:WA5Qsk0HkDHSiNaTD3oWZ0IsqkPxpPHKBHEcF9H/2q:/5C0HCS+aTDYWCIdkxdHKBHl9Heq
TLSH BC1533B2F2A5F29C5BB918F6CEC7706C87C8855A41C44A0B148647B21FAE5DA0FED4D3
Reporter abuse_ch
Tags:gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: smtp01-sa.serv.net.mx
Sending IP: 201.150.39.117
From: Karla <ventas1@flexijuntas.com.mx>
Reply-To: Karla <officejb01@mail.com>
Subject: ORDEN DE COMPRA 28466
Attachment: Orden de Compra lista.DWG.gz (contains "Orden de Compra lista.DWG.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-15 07:55:22 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz 171b30ee0e7bc1041ab080338ade87eb5b1db21b2764a5e0c65fddd88fdb6555

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments