MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c2b47e1ca0d79178355456250289da4f1376b8b8d2ea0b883b1ab1c174f58a63. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | c2b47e1ca0d79178355456250289da4f1376b8b8d2ea0b883b1ab1c174f58a63 |
|---|---|
| SHA3-384 hash: | ec4073822731f9519a4f3ca4c77b57ca89ef2e8e5af9647505f2965d737ecabdad64489671d9b994df0e319d6c9ebfb7 |
| SHA1 hash: | 6a5d51b4ea0de0a258d5bf74a2e28a78b81bf3e8 |
| MD5 hash: | dfa7ec7b62eaef2a90c3aa4d61ccfcf7 |
| humanhash: | mike-aspen-thirteen-echo |
| File name: | Quotation Request Form.cab |
| Download: | download sample |
| File size: | 407'965 bytes |
| First seen: | 2020-10-07 05:15:50 UTC |
| Last seen: | Never |
| File type: | cab |
| MIME type: | application/vnd.ms-cab-compressed |
| ssdeep | 12288:BLikiNTkhfcyhNfvvpFnaGl6FSu7t1jXd:pJiNTcrfJBQvPjt |
| TLSH | 52842320E8141EC7FA395130AC974512EA3B1C789160C44DF1E7BB07EB739F9ABB54A6 |
| Reporter | |
| Tags: | cab geo KOR |
abuse_ch
Malspam distributing unidentified malware:HELO: mail-smail-vm87.hanmail.net
Sending IP: 211.231.106.162
From: 견적의뢰서 <hanilnc@daum.net>
Subject: 견적요청드립니다.
Attachment: Quotation Request Form.cab (contains "Quotation Request Form.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-07 00:42:31 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
cab c2b47e1ca0d79178355456250289da4f1376b8b8d2ea0b883b1ab1c174f58a63
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.