🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 200b16b4b38eaa85db2a040f521782ff508949139711dab6a32b93cf078411bb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 200b16b4b38eaa85db2a040f521782ff508949139711dab6a32b93cf078411bb
SHA3-384 hash: 66dab3cfcb8e9a77b9e945ec2b16c12a50561206081698fb21564de8aa13da3b065a6da4043b51838799cda3593d4ed0
SHA1 hash: 5b1c623feb44ccf65a6559b16077a3e78115c7d2
MD5 hash: b5ede0ff77517fdf30a66dea5bf78d61
humanhash: nine-seven-jersey-yellow
File name:claim-nov-2-169EAO249-23.pdf
Download: download sample
File size:212'456 bytes
First seen:2023-11-03 17:06:37 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:iai3/or3B8vmAii7rmHww2ArEJmR7uPdRSAJF/f8:iai3Ar3KnrmQw2A4OAdRPF/E
TLSH T1282401A83435C450DD9BA5B11B5C3FC3A5CBC1F218D62023D072AA9F367EC23B4A15EA
Reporter Anonymous
Tags:pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
471
Origin country :
US US
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
4.0/10
Score Malicious:
41%
Score Benign:
59%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
phis
Score:
22 / 100
Signature
Suspicious PDF detected (based on various text indicators)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1336834 Sample: claim-nov-2-169EAO249-23.pdf Startdate: 03/11/2023 Architecture: WINDOWS Score: 22 32 Suspicious PDF detected (based on various text indicators) 2->32 7 chrome.exe 1 2->7         started        10 Acrobat.exe 20 74 2->10         started        process3 dnsIp4 22 192.168.2.6, 443, 49702, 49703 unknown unknown 7->22 24 239.255.255.250 unknown Reserved 7->24 12 chrome.exe 7->12         started        15 AcroCEF.exe 67 10->15         started        process5 dnsIp6 26 accounts.google.com 142.251.16.84, 443, 49732 GOOGLEUS United States 12->26 28 142.251.167.104, 443, 49761 GOOGLEUS United States 12->28 30 8 other IPs or domains 12->30 17 AcroCEF.exe 2 15->17         started        process7 dnsIp8 20 23.55.204.134, 443, 49727 AKAMAI-ASUS United States 17->20
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-11-03 16:58:05 UTC
File Type:
Document
Extracted files:
58
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments