MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fce8832139dd4fd0e3e68014c9f3d270d563002de976c002dd3f566e0f99dc7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5fce8832139dd4fd0e3e68014c9f3d270d563002de976c002dd3f566e0f99dc7
SHA3-384 hash: 5b0c30c66ce90d3ac70ef8bbc5ad3a726d5fb53d338aff40385948dd35e80441abc5dbef0cdc74530c708685e1954261
SHA1 hash: 9f10c700da2407e6fdce63fc58f87a945dc60d39
MD5 hash: 957cb50daa639942233129bd26d2c608
humanhash: mirror-mockingbird-four-cup
File name:K95 MASK-QUOTATION-SHEET3432,DOCX.rar
Download: download sample
File size:334'582 bytes
First seen:2020-05-18 05:57:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:OLhAiLHPwIDq+TT7TCcbkn+vOsamgW60doGhGJRmLBwqLbvwWtgB0O4q0mspd:O1t5q+TT7T1bk+l16u6+Bwq3vJ59d
TLSH 326423B1925E88761B7AE7DB211CDE9E22CCB38F4BB258F14301CD42E6283A5375D346
Reporter jarumlus

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-18 06:35:50 UTC
File Type:
Binary (Archive)
Extracted files:
19
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

rar 5fce8832139dd4fd0e3e68014c9f3d270d563002de976c002dd3f566e0f99dc7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments