MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb02a11045cf8bb9edf9c788e1cd940b04f3ec53d003b17b5a00e8fe44c7e869. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: bb02a11045cf8bb9edf9c788e1cd940b04f3ec53d003b17b5a00e8fe44c7e869
SHA3-384 hash: f254dfdc51d002c295b538f9634c8ae2d4010582cac4fb23571736b82c73d3f9aa052e84aa53e6e55fedda2e2fdd0fe4
SHA1 hash: 1f121c6db5d944d3d09d5948f8d8e106874f6312
MD5 hash: bfcc84bd9ae0bcd001fadecfc68fd27a
humanhash: pizza-uranus-fruit-foxtrot
File name:OrderQuantityQ#3.zip
Download: download sample
File size:15'745 bytes
First seen:2021-02-03 12:21:16 UTC
Last seen:2021-02-05 17:23:40 UTC
File type: zip
MIME type:application/zip
ssdeep 384:tZe8ttzuGrBnn/3UK1U7af/FuPKRpbEwc:tZxhrpsC1/FuPKfFc
TLSH 4662C0DB60048120A46AD77FF966D67706A18824267F6E75BC0F8531AB9087427C0F93
Reporter fabjer
Tags:zip

Intelligence


File Origin
# of uploads :
4
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2021-02-03 11:16:16 UTC
AV detection:
15 of 46 (32.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip bb02a11045cf8bb9edf9c788e1cd940b04f3ec53d003b17b5a00e8fe44c7e869

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments