MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c85e47e35a33d2daca8862e0a952696e16661e72f66b8db490809e1d835a3f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6c85e47e35a33d2daca8862e0a952696e16661e72f66b8db490809e1d835a3f1
SHA3-384 hash: c09f29c1a7ba3f829c5469d5271aeb5586cbe3cb047be3cd003518dc67509ebaab3c59785cbefe04379d265e7aecf547
SHA1 hash: 3fa05538535084d9f54f461b08c931c96298fdb0
MD5 hash: 04c737b54499bbb583cbf0efd4b2f027
humanhash: william-march-comet-black
File name:Delivery Note AWD 2099282722-202929282.gz
Download: download sample
File size:1'180'665 bytes
First seen:2020-08-04 16:36:02 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:G1i4fUuMbrQOhW5QCNmdnSX8/Ok5snJLUFdA:0/fUuUCNmdSX8Gk5snK6
TLSH 7845331AC752E41B80F11B63814589DD559DE3FF98C1D134B8CAAE90EFB4A8F8DEB811
Reporter abuse_ch
Tags:DHL gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: server.manisanet.net
Sending IP: 89.252.178.16
From: DHL Express <katewright_dhl@gmail.com>
Subject: Failed DHL Delivery Notification
Attachment: Delivery Note AWD 2099282722-202929282.gz (contains "Delivery Note AWD 2099282722-202929282.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-04 16:37:05 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

gz 6c85e47e35a33d2daca8862e0a952696e16661e72f66b8db490809e1d835a3f1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments