MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1533374acf886bc3015c4cba3da1c67e67111c22d00a8bbf7694c5394b91b9fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1533374acf886bc3015c4cba3da1c67e67111c22d00a8bbf7694c5394b91b9fc
SHA3-384 hash: 25517adc0034950916ec505d1791b7796eac8aa152022bea13bb84aa015b61db28a1d6ebc95738364fe247685de17408
SHA1 hash: 8af1c8c44d321209492c0c73c8ae25f8265833d4
MD5 hash: 2d27e4aa3315c7b49ce5edd1a3fb5485
humanhash: purple-mobile-oranges-maine
File name:1533374acf886bc3015c4cba3da1c67e67111c22d00a8bbf7694c5394b91b9fc
Download: download sample
File size:290'816 bytes
First seen:2020-08-25 14:14:36 UTC
Last seen:2020-08-25 15:06:04 UTC
File type:Word file docx
MIME type:application/msword
ssdeep 6144:4qeZW6uUGwGOMpsdmQsNW/74kGldaeoEISB8:4qdlUvfMeETNCkkNt
TLSH 8254CF627391FD32D5560435EC06C3EAA626FE499FA5829B30C13F2F79325212A53FD2
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file
Running batch commands
Creating a process with a hidden window
Launching a process
DNS request
Sending a custom TCP request
Launching a process by exploiting the app vulnerability
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
84 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to a URL shortener service
Document contains an embedded VBA macro which may execute processes
Document exploit detected (process start blacklist hit)
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Behaviour
Behavior Graph:
Threat name:
Document-Word.Trojan.GenScript
Status:
Malicious
First seen:
2019-04-04 07:34:39 UTC
File Type:
Document
Extracted files:
19
AV detection:
26 of 47 (55.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Office macro that triggers on suspicious action
Suspicious Office macro
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments