MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7451fbb7aae1790131e38c71111a77549433a8e6ab5ad29401f70c1c3e545af3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7451fbb7aae1790131e38c71111a77549433a8e6ab5ad29401f70c1c3e545af3
SHA3-384 hash: 7e8d1a1cad3e0f060d3ff788d3892cd242a42138d117a2b7691659e813cfd9301286474449a5f6d06d5de8b2c162e449
SHA1 hash: 11f9ff80568e7a75da35258348af1951dbe29d39
MD5 hash: d077692a9b7f025dae183f7fdfe6c37d
humanhash: harry-april-hot-charlie
File name:SB15572.cab
Download: download sample
File size:420'927 bytes
First seen:2020-10-07 04:42:06 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:EPDw/z69APZopKeyjNzwlk5sPXP7+hrj/lXbkvP/KdOq53Vm39P3SxOwy3T7:TzHyQey46+ChrqvPI5FAP3Scw47
TLSH B59423E48CAC3911F54F4D8A433DDCB53077AC7A1EE6928A984370758E7A9134F89E29
Reporter abuse_ch
Tags:cab


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail-smail-vm49.hanmail.net
Sending IP: 203.133.180.237
From: 김재현 <cjfilter@hanmail.net>
Subject: 견적 문의의 건
Attachment: SB15572.cab (contains "PO.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-07 02:11:01 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

cab 7451fbb7aae1790131e38c71111a77549433a8e6ab5ad29401f70c1c3e545af3

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments