MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c6fe81df56d72c68cc024b1f0fd2cfff15d5357532e095715c2ee5112f5bf5f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8c6fe81df56d72c68cc024b1f0fd2cfff15d5357532e095715c2ee5112f5bf5f
SHA3-384 hash: 2d7496ecadd1fc5b2df569574682fdb064114b53aceb6c92f0fc1f0ccedacc35c46d4a4970dcf08588230157acd25cdd
SHA1 hash: 417af58eed8cf5d669e1069adc7ba12bb0ba18ed
MD5 hash: 16b80fc3a749a2c4a0cd9b23225ae106
humanhash: edward-april-minnesota-kansas
File name:Payment_Invoice.zip
Download: download sample
File size:930'355 bytes
First seen:2020-10-19 09:54:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:D8s6rfIsjtv2HUIzixVlziF7uC1GEFbImqr7Nt:D8skAm4ziNm71GEt2/H
TLSH 37153347700F6D07AA3659D9C4EF9C28751A00F158A3A7D1065C0FA6ACF77EE49E87E0
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: dd48220.kasserver.com
Sending IP: 85.13.164.135
From: Quality Engineering Products <christiane.helf-marx@akadia-akademie.de>
Reply-To: snambrath.almandoos@bk.ru
Subject: Re: Payments - October Invoices
Attachment: Payment_Invoice.zip (contains "Payment_Invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-19 05:08:51 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip 8c6fe81df56d72c68cc024b1f0fd2cfff15d5357532e095715c2ee5112f5bf5f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments