🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08e8817f4907bf34530e1dc56bbe20fbff4b027171f5df7907b3aa5ce6346b65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 08e8817f4907bf34530e1dc56bbe20fbff4b027171f5df7907b3aa5ce6346b65
SHA3-384 hash: c5d83917f69766cc1a2723f2b883d0add46409620accfde1e41e4c34e5d31ea3d93dc7761e553bf062d26fc875ffa710
SHA1 hash: 94b8f800580df9a5cf2f2f5d22e48d78bbcb2c41
MD5 hash: aed334fb3f0335ff54f8e5fa8476ace8
humanhash: tennessee-minnesota-uncle-north
File name:Shein Fashion .pdf
Download: download sample
File size:179'373 bytes
First seen:2024-08-03 17:21:06 UTC
Last seen:2024-08-04 13:11:59 UTC
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:KqZ5+8ikhsYETm4uIUiVU92oadQVch9iS2BPcYvrUzp89kUOsCWymAVXOg6I:VZ5iWf0mriag9v2BPc6rU1skUkWymA9j
TLSH T1E004123BD56CAC85CA7994B9057A80B3788DD23A83D6DD07AD81F0EE0A42D5B578C3C9
TrID 61.2% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
31.5% (.ZIP) Open Packaging Conventions container (17500/1/4)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Reporter cocaman
Tags:pdf xlsx


Avatar
cocaman
Malicious email (T1566.001)
From: ""9508085209:ID.Marriott" <nicolas.alzategch1e@elect.fcrit.ac.in>" (likely spoofed)
Received: "from MA0PR01CU009.outbound.protection.outlook.com (mail-southindiaazon11020091.outbound.protection.outlook.com [52.101.227.91]) "
Date: "Sun, 04 Aug 2024 13:08:30 +0000"
Subject: "TR: 242765:ID You have won Marriott Luxury Pillows 2-Piece Set ID:w5j1je"
Attachment: "Marriott 26589.pdf"

Intelligence


File Origin
# of uploads :
3
# of downloads :
2'916
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Postnord 25789.pdf.zip
Verdict:
No threats detected
Analysis date:
2024-08-03 15:56:58 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Using the Windows Management Instrumentation requests
Creating a window
Сreating synchronization primitives
Result
Verdict:
Clean
File Type:
OOXML Excel File
Document image
Document image
Verdict:
Unknown
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2024-08-03 15:43:21 UTC
File Type:
Document
Extracted files:
36
AV detection:
2 of 38 (5.26%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Excel file xlsx 08e8817f4907bf34530e1dc56bbe20fbff4b027171f5df7907b3aa5ce6346b65

(this sample)

0666675fa87fe39d8a2efa286e2ebbf47ae0ea8f944acde61a3fb88870eaaf1b

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SHA256 0666675fa87fe39d8a2efa286e2ebbf47ae0ea8f944acde61a3fb88870eaaf1b
  
Dropping
SHA256 ad78dfe44ec71f967f96e95bdf6baf2545c39e1a5e4413e7b8e9413eb95fd922
  
Dropping
SHA256 0c90de5c5728d1514cfd2eb5b27c06f1dc1edeb4bd758aa0a101347dc70d8424
  
Dropping
SHA256 6f044ef390b74876c4f2f77fd00d0543363235effb2711cd374e30f8690448f0
  
Dropping
SHA256 4138a743889a12a32d3bd885631c7690643bc2a3e8f30f29fb579b2ce268036e
  
Dropping
SHA256 ed53a1f02d5d3b3790bc160ed14b0efee96dd309f0a3243f3e10e13d8e3aaf87
  
Dropping
SHA256 d58ec85a373eef821a592a60605b29c30502bd86282e3dd49383fd4f0f2a1f8c
  
Dropping
SHA256 54ca908dab2fc8f2b2292c7601f23195fc55f8067d78a4263c2689678bcf0082
  
Dropping
SHA256 e14018a9060c92217ce2c15f2e10c3862e5a60bb3ad4e65cae06b511b6ff08ed
  
Dropping
SHA256 145e5e11283f072798dd20abb764dc28d1ebd70c7579ddce28822ea459f04364
  
Dropping
SHA256 ce511f6b464f7437c4e005b145a17a101b9725bb09dd8303b59ac7541be676d3
  
Dropping
SHA256 ee9fa12d10c5ee0ae23c711aad3be36f1d99d87934a588aac4ecaf1028bdef16
  
Dropping
SHA256 d9ce9dac22a848ed1333d64de9f1b8e804e339906b6d71fe2ba08cc27b7e3928
  
Dropping
SHA256 55dcc4ac09f0b4828a5e4138ffe799fad22be0c8e8705431b0c6f79144510605
  
Dropping
SHA256 99d58108b2fc0a2ebc5ff913c807eedf33276485c872f3d387bf26d215ba9126
  
Dropping
SHA256 61aebd8269b3a4b706441c6075a1c214763afae205262f6fc46d61415de8288a
  
Dropping
SHA256 1994d038968ac361e6713e1030b9cb29b4be221ecdd37561deb5172664cc239c
  
Dropping
SHA256 9cb4f8544950a79050a442586cb3e046b186df565e868aaf182d2c0898b3b9be
  
Dropping
SHA256 0dfd39236a9671b7db10a648b9e3d10fdf64f2e13b1feed0f21d30c4fe9c7fa6
  
Dropping
SHA256 e100ade9247237f6feebee3f0d6931b5481d51ed0d9cc679b301e1fa18dfc43b
  
Dropping
SHA256 0a193f2c7f17ae551127d6e416fa36af0bdd28b5f47c8c5d3ca521b87826fefa
  
Dropping
SHA256 c6ab378ee31cdad7c45e4a9134006ff17fbc2d5a95377633a1fc8c0e39a36bc1
  
Dropping
SHA256 cd1b05da76e24dff4a877972cedc86e40a5260f2823bdea3b5665a81eff9a0da
  
Dropping
SHA256 5efcaf9ad70d9c29f406ee438f8f428b021a881d2c5afff0e53b00b1f67ae51e
  
Dropping
SHA256 50932fefa05af7d439305a402207d007de878e1e9b81e5caabca45ee5c4a2508
  
Dropping
SHA256 2a6aee4c8a9714223a3568077411a0c82d11b484b1c9ab93a19d50b99c57baa5
  
Dropping
SHA256 3aa4054f7f463c6d441102c960783aa7f937d6945a0a885b624a66aafaeedb6c
  
Dropping
SHA256 5ccbe389789798ef7c781509ad2ed4ee9dc0abaf3fbef3196275ddfbb66edd24

Comments



Avatar
commented on 2024-08-05 10:14:19 UTC

Found more variants of the same campaign. What is common in all :
1. The sender starts always nicolas.alzate<5_chars_or_nr>
2. The file hash is the same 08e8817f4907bf34530e1dc56bbe20fbff4b027171f5df7907b3aa5ce6346b65
3. The file name ends always as "<space>25789.pdf"