MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4773cee4161b68ccac5f5f23a8de79d4b7130b6f06e175f62941a925f3c1155c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loda


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4773cee4161b68ccac5f5f23a8de79d4b7130b6f06e175f62941a925f3c1155c
SHA3-384 hash: b8a20907421afefebb94636af0b9aee8c1d82ed5589320d001e41842f974eff762a970f9b570484dc877085086e2f52c
SHA1 hash: c6df0e667ced553adac4fe3e7ab4205aca1702c7
MD5 hash: b09e4e7d11e55f678378b29802471c48
humanhash: quiet-glucose-one-november
File name:captura de pantalla.pdf.z
Download: download sample
Signature Loda
File size:818'708 bytes
First seen:2020-10-13 12:30:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:+yhcXhchpxvuUfo1UR2i6ZehDN5WkEZtt/x:NcXhchvv7fo+AYN5jEbx
TLSH 2205335E59F69405A9F947323EF706F82EC0DF9787965C89E43C8EB866200A2471353F
Reporter abuse_ch
Tags:Loda z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: box0.fima-logistics.com
Sending IP: 194.15.36.155
From: Javier Bardem <office@fima-logistics.com>
Reply-To: <mobilecommunications@vivaldi.net>
Subject: pago de nueva reserva
Attachment: captura de pantalla.pdf.z (contains "captura de pantalla.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-AutoIt.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-13 12:32:06 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loda

zip 4773cee4161b68ccac5f5f23a8de79d4b7130b6f06e175f62941a925f3c1155c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments