MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c9d2c756ec211e2a94a253bb04214d8be64b9f0f767d68bd88ec84d74e273ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6c9d2c756ec211e2a94a253bb04214d8be64b9f0f767d68bd88ec84d74e273ae
SHA3-384 hash: 9da7371b11e7fa2ba20334570eb7cd129f9dd18cce133783c06c7c13b96f9cc6e3134a214c4d8d55d70d633332c12402
SHA1 hash: 7169486f1a997f634527933aa85036bb0f661b80
MD5 hash: 46afc60c18db5b9f7c12ec3a2e02a8bb
humanhash: winter-seventeen-hot-neptune
File name:Company profile.zip
Download: download sample
Signature AZORult
File size:399'160 bytes
First seen:2020-10-02 06:44:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:SaKiMGJ3pubiPWUpkPd3QZmrOBo7GMBOLy9kj:SaKFziP/6Pd3NOBKPBOLy9kj
TLSH 738423D8DBEC8645080DF3BFA693D850751290F785BDB5C164769EB886E3CFA6638308
Reporter cocaman
Tags:AZORult zip


Avatar
cocaman
Malicious email (T1566.001)
From: "CARME MOLLET <karolina@realpharm.eu>"
Received: "from server.sgbcg.com (server.sgbcg.com [113.11.251.241]) "
Date: "Thu, 01 Oct 2020 14:18:29 +0800"
Subject: "INQUIRY: Request for prices and lead time"
Attachment: "Company profile.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-01 07:19:59 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

zip 6c9d2c756ec211e2a94a253bb04214d8be64b9f0f767d68bd88ec84d74e273ae

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AZORult

Comments