MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1c7f5fe270ab863c0bd203a13744df66ff561a778d10395de8149179f5fc59e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a1c7f5fe270ab863c0bd203a13744df66ff561a778d10395de8149179f5fc59e
SHA3-384 hash: c7258bc065cdefc838e8c182f39b8b95d560c21651f38771a7ab13499ea938b8a6a479b9bf3869e3f450de4d2cc2edc8
SHA1 hash: b3a4fc3365f93f4a756c027f4e2799b134337cdd
MD5 hash: 81456c72ff3e7d7e4ea1a20c8645d9ba
humanhash: nine-robin-india-nevada
File name:order details.xls.qa.zip
Download: download sample
File size:508'683 bytes
First seen:2020-11-05 11:44:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:bwX3u7PS0ZozlYmqDqoIZLg/8GEopaTHMAGHhksJ:Q90ZozlYm7oqYKHMnuG
TLSH 89B42311764025083A76E5FFBE2AB32A6402D26975280778845EFD21F93C7DEE5ABF40
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: ericlos.net
Sending IP: 192.187.120.178
From: Kedar Deshpande <contact@ericlos.net>
Subject: Purchase Order Details.
Attachment: order details.xls.qa.zip (contains "order details.xls.qa.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-05 10:16:46 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip a1c7f5fe270ab863c0bd203a13744df66ff561a778d10395de8149179f5fc59e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments