MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 eb59bae9f80f008f75b2808788a0802eda30c8bd52622266c8bf4572a8a56a4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | eb59bae9f80f008f75b2808788a0802eda30c8bd52622266c8bf4572a8a56a4f |
|---|---|
| SHA3-384 hash: | 1648de0a799ba74f115632a8f392c83948c0a599df6e6761572718ffa6aa43a3031c864e90c248e2fddc4a51937ab0cc |
| SHA1 hash: | fa24e90546c5eece7f7255d0b04ffe11ff17aeba |
| MD5 hash: | 88e51d97aa4f7b0cba42ce706d34bee2 |
| humanhash: | network-fish-venus-item |
| File name: | Request For Quotation ALE-YQ-326962-20.gz |
| Download: | download sample |
| File size: | 245'017 bytes |
| First seen: | 2020-10-14 15:04:20 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:pgfbaIrKCigxpaNwS1iuVnp2MkLGj5BRjG/DOnQhobOs4Rdgcdu:pgj7KCimkOlOnUMku5BxGqQckPgl |
| TLSH | 1F3422E7C0B28F954E18C20F51DD8E935EC9F07A65CD016F23CA68716EE7A94AB6CD01 |
| Reporter | |
| Tags: | gz |
abuse_ch
Malspam distributing unidentified malware:HELO: cera-india.com
Sending IP: 185.222.57.210
From: KARAN PATEL<paymentadvice@cera-india.com>
Subject: Request For Quotation # ALE-YQ-326962-20
Attachment: Request For Quotation ALE-YQ-326962-20.gz (contains "Request For Quotation ALE-YQ-326962-20.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokibotCrypt
Status:
Malicious
First seen:
2020-10-14 00:37:07 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
gz eb59bae9f80f008f75b2808788a0802eda30c8bd52622266c8bf4572a8a56a4f
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.