MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e3317df95f6c236bdb7f7761b1b3c839100c89797f9ae52eedc9daed96f7bbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0e3317df95f6c236bdb7f7761b1b3c839100c89797f9ae52eedc9daed96f7bbb
SHA3-384 hash: 54f83c9bd32ae50f2d64e3600aff847a63db001c2d46ba097b4be2b8b57f4316cfbe47a1fab79ec732e3fdd27356dc38
SHA1 hash: 3a90b67112d9d36e2283620d1f0dad966ef8cc8a
MD5 hash: d5c6c427a95a91ee691b9cebdf8a56f4
humanhash: illinois-don-helium-lemon
File name:invoice-1645080830.pdf
Download: download sample
File size:40'420 bytes
First seen:2026-06-26 05:49:08 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:+nl241osPjFLjhdlCxJPxncS45sJflFbfhfhfhfhfTZZZZZZZZ61J:6l24lpdCxJZnjWsh3bfhfhfhfhfmf
TLSH T16D032B538C995E43A878C7A9BF470F6D6F497D4EA4827AFF302E0D867B312605C0D16A
Magika pdf
Reporter JAMESWT_WT
Tags:account-bookings-vercel-app booking pdf Spam-ITA

Intelligence


File Origin
# of uploads :
1
# of downloads :
341
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
macros
Label:
Malicious
Suspicious Score:
6.1/10
Score Malicious:
62%
Score Benign:
38%
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
PDF /Javascript PDF /OpenAction PDF Contains AutoAction PDF Contains Javascript
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2026-06-26 02:19:17 UTC
File Type:
Document
Extracted files:
6
AV detection:
4 of 24 (16.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments