MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 053fce99aede46ff51c2f97ad899078ac08a0a6ea15055507a651bc7648a8409. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 053fce99aede46ff51c2f97ad899078ac08a0a6ea15055507a651bc7648a8409
SHA3-384 hash: 7b4b9035e6191f210f5ab77c2b53dc46b52edaae2381c6a25ce71703b13351f7176ba2d5e0da5d6e10ef577edbe9204e
SHA1 hash: b15f88b3b32d1f1595169c26bd49ad0d4aa8dfc6
MD5 hash: 18a0816a3d55a14d2c162ba8431c64f5
humanhash: one-tennis-ten-nuts
File name:INF34747.rtf
Download: download sample
File size:127'984 bytes
First seen:2026-08-04 08:41:08 UTC
Last seen:Never
File type:Rich Text Format (RTF) rtf
MIME type:text/rtf
ssdeep 768:2vA6Qx1lv+8sOuTA5NuLUZjBK/YnPq+teLo14PBgKT4i87csb5ftkLFFI3kShY8W:2neOpBQ8voHpOXF
TLSH T157C342745C16E7C6C632871AE9AFB1CA9534F00A88F934E992FE0347847FE152DAB447
TrID 83.3% (.RTF) Rich Text Format (5000/1)
16.6% (.JSON) JSON object (generic) (1000/1)
Magika rtf
Reporter abuse_ch
Tags:rtf

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
rtf
Verdict:
No threats detected
Analysis date:
2026-08-04 09:00:12 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/rtf
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-04 09:29:21 UTC
File Type:
Document
Extracted files:
2
AV detection:
3 of 24 (12.50%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments