MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1262d580e57131c04be11865d5ff151e78cadce3dfbb78b2e0f3865a293dbda. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c1262d580e57131c04be11865d5ff151e78cadce3dfbb78b2e0f3865a293dbda
SHA3-384 hash: ef174efe4ca058eae2bdf90dfbf3494b5d4f50b2911412b413afdbaeb045b97d162cf4ac3bf927afea8e358e95e285ba
SHA1 hash: 67d5ad178fba0f49704ecab615246c7aafdf4e06
MD5 hash: 45ae8ea15de3e0c865da71f0fd9c1a6a
humanhash: shade-mobile-west-four
File name:EVS-1550-Gauge.zip
Download: download sample
File size:800'974 bytes
First seen:2020-08-13 11:17:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:tcPcRkN3LIsz0ZTElJ/PaACXVz3bVFsAi:tcERW30PTElJ/SAGbfi
TLSH 6B052352C24016E90936E9DC2FDCBCA3ABA04FCCBD7578B24D89E4734511B50B93DA76
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.pickelhost.com
Sending IP: 104.168.243.73
From: 'mayurzala@chemprosys.com' <vladan.vlaskvioc@gmail.com>
Subject: EVS-1550-Gauge Inquiry
Attachment: EVS-1550-Gauge.zip (contains "EVS-1550-Gauge.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-13 08:50:49 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip c1262d580e57131c04be11865d5ff151e78cadce3dfbb78b2e0f3865a293dbda

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments