MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05dc0792a89e18f5485d9127d2063b343cfd2a5d497c9b5df91dc687f9a1341d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: 05dc0792a89e18f5485d9127d2063b343cfd2a5d497c9b5df91dc687f9a1341d
SHA3-384 hash: 3b6981ed6036a5d1358593d920d66be7632b5021ba41683addbcf9069b517bafa7a2e22cf4d1151d45c79d6b254ddae6
SHA1 hash: ff0979fbfc57104e431e0fb1c1107859789f913a
MD5 hash: a3a7e49226d703a4aee1d227c6f441e6
humanhash: nebraska-leopard-finch-steak
File name:a3a7e49226d703a4aee1d227c6f441e6.vir
Download: download sample
File size:36'894 bytes
First seen:2022-03-24 16:54:12 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:U4Rbq60M/x3qz7t+5uU6F1Rbq60oBRBsFWH9zuCFPpJz8e/KQ2CM3QbrG8vKhqFl:Uq+k/RO/FD+ORNN/Ie/hZrvKoFLp
TLSH T130F2D0E872B089DAD643C4396E91138A81ECD852877DE42E6108C6143F2CFDA7DB095F
Reporter DSTLabs
Tags:pdf


Avatar
DSTLabs
Malicious PDF with embedded .DOCX file.

Intelligence


File Origin
# of uploads :
1
# of downloads :
582
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
CVE-2017-1188
Label:
Benign
Suspicious Score:
4.8/10
Score Malicious:
49%
Score Benign:
51%
Result
Verdict:
MALICIOUS
Threat name:
Document-PDF.Downloader.Tnega
Status:
Malicious
First seen:
2022-03-23 16:09:50 UTC
File Type:
Document
Extracted files:
22
AV detection:
12 of 26 (46.15%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
TomU | I'm still here... til the end commented on 2023-03-29 12:17:21 UTC

similar PDF samples with embedded DOCX / XLSX files, presumably abusing EQNEDT32.EXE vuln to D/L malware EXE (mostly FormBook?)

de457b7a5b35e40bb74d462e3d7b7dbf ./PURCHASE_ORDER_234367_DRAWING.pdf
f88ca2a1319b42250a8377da12c33c54 ./FirstXsettlement_ContractXA15.pdf
30bbabb6cfec7500b78fc99c23a89bd4 ./Invoice-TransferXDetailsX03062022.pdf
0000cb9106ed36116996fbadfa78b906 ./purchaseXorder.pdf
0a8558a36775a1e5656ed56716bd4412 ./ShippingXDocument.pdf
d60a24ac861fdef34edb3ddd0ec3bb23 ./Proforma_Invoice.pdf
b2591c40ae4c88c484bd0be92cd04f16 ./PagoXEURX34,650.98XWERTHHHHHH.pdf
c019598acb3228540832fe3eae4853bd ./SC01083B00191208SCHK.pdf
d79c7d4f6a038753bbc681176ec83c42 ./PurchaseXOrder.pdf

"has been verified. However IMG, PDF, doc, .xls"
hXXp://103.167.85[.]227/M55190/vbc.exe