MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87726af09e679befd9d3557ed1f30fc211e6baff4e84f7d8fcd310779e3c8d9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 87726af09e679befd9d3557ed1f30fc211e6baff4e84f7d8fcd310779e3c8d9c
SHA3-384 hash: a29bc12150f9ed742accbfe4ae7ef0b04fe4037e53d3194de9da2f13f90459e62a8df6edbc3598497379c5c5e772aa9d
SHA1 hash: 7dab0ca7ab61853a5a81a64c41effac6b88da943
MD5 hash: 1f78e8a67e597f35c96a503645c88243
humanhash: twelve-solar-grey-xray
File name:Payment Details.zip
Download: download sample
File size:436'419 bytes
First seen:2020-08-14 15:38:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:yQpYTj8/bTOUj/EukOb0PT/QzPw40YKYAHxKg+v93uCl/S:gTY/3RkOgb/EeTcHq
TLSH 599423D139B0FB95031A4C65F9F7E0CE520A5926CD7CD6F1D06A3B61E17AD82E2231E1
Reporter abuse_ch
Tags:Hostwinds zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: hwsrv-759639.hostwindsdns.com
Sending IP: 104.168.219.207
From: info@losshic.com
Subject: Original BL
Attachment: Payment Details.zip (contains "Payment Details.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-14 15:40:08 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip 87726af09e679befd9d3557ed1f30fc211e6baff4e84f7d8fcd310779e3c8d9c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments