MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93044b2a5890a044c911a6ea8323104e793c6c1106baf9f473e84c252793a4b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adwind


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 93044b2a5890a044c911a6ea8323104e793c6c1106baf9f473e84c252793a4b5
SHA3-384 hash: 1bfb7582c4e9347b6ce279dccfd78752f7b78c50d3935e04803b3b1f21e3d6114125a6fab5602dc1778fd1dd3ef990ac
SHA1 hash: 8e6bee0e5a7cc5fe231e4e989e9489f67f8974b4
MD5 hash: a4206deefa41f8ef405f1b2fffb266bd
humanhash: ten-jig-michigan-grey
File name:Payment Confirmation invoice Nr 002956.zip
Download: download sample
Signature Adwind
File size:104'412 bytes
First seen:2020-05-11 15:10:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:kn1Jxvv26uF0q5ePYu0H4kuEh3ud84jujT/K7b:kn1Dv2PpiY3HlmwvC7b
TLSH EAA313463366E03DFDA910E0F5B1113FA2A39D31D85A8A4277BC01CEC26ABC64D1E5F6
Reporter abuse_ch
Tags:Adwind zip


Avatar
abuse_ch
Malspam distributing Adwind:

HELO: deliveryinfomails.com
Sending IP: 69.195.145.142
From: Anker Nielsen <info1@xpresslinkmail.com>
Subject: Re: Fwd: Deposit Payment For Proforma Invoice
Attachment: Payment Confirmation invoice Nr 002956.zip (contains "Payment Confirmation.jar")

Loki payload uRL:
http://ratamodu.ga/~zadmin/iclient/tel_uBbcQLoYme226.bin

Loki C2:
http://egamcorps.ga/~zadmin/lmark/tel/mode.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-JAVA.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-12 04:26:52 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Adwind

zip 93044b2a5890a044c911a6ea8323104e793c6c1106baf9f473e84c252793a4b5

(this sample)

  
Dropping
Adwind
  
Delivery method
Distributed via e-mail attachment

Comments