MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bf56b8f9babb8ff4d2207d39999a2ef0a485a7abb1248f46b8cf470b959a3571. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 2
| SHA256 hash: | bf56b8f9babb8ff4d2207d39999a2ef0a485a7abb1248f46b8cf470b959a3571 |
|---|---|
| SHA3-384 hash: | c893f87cb83945702eac92b247cbc6b280edb1d3aa82ab2c7a9141b6ccdb8113e49e7eee63dbd47bca1d8b41a15e8abd |
| SHA1 hash: | 90f7f7a983d35ab99ddde4d9ecf815467f763eea |
| MD5 hash: | a43265b819ce67881c3a2fea4085a5c2 |
| humanhash: | spring-johnny-kilo-kentucky |
| File name: | job_documentation_68307.zip |
| Download: | download sample |
| File size: | 320'546 bytes |
| First seen: | 2021-05-18 09:18:42 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:rU1Oj+swdQR49Or7KfVRG1E2eKK2Ue1Rd3oncwaZLdY33nzqHSjVFz:4Ryi9OXATG22eKVUe1L3ocwaT0zISjf |
| TLSH | C96423525DCC5F77E4682FED77AD9A373EFA2912BC30D68420EB5A730A02510387536A |
| Reporter | |
| Tags: | pwd: 8888 remcos vbs zip |
edelahozuah
Password-protected ZIP file dropped from Onedrive link embedded in the email body. Password also included in the email body. Likely RemcosIntelligence
File Origin
# of uploads :
1
# of downloads :
211
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Script.Trojan.Wacatac
Status:
Malicious
First seen:
2021-05-18 09:19:07 UTC
AV detection:
1 of 47 (2.13%)
Threat level:
5/5
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Delivery method
Distributed via e-mail link
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.