🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 218a02f75f3562c0c91c38c67e86a9fb5e0a96db07381bd5d4875f360fc35bf0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 218a02f75f3562c0c91c38c67e86a9fb5e0a96db07381bd5d4875f360fc35bf0
SHA3-384 hash: 2f1eab7df17311e3c7cb95da900552b026680483c34dc6f286b9f5bc7019155c3ca3eb5337a55e4a793c8213b8e76f40
SHA1 hash: 687ffa86d92a9e7365093d75a2fad8b34421915d
MD5 hash: 97bfb545bcbcac2f46f1c2f9d609e10e
humanhash: music-maine-uranus-high
File name:Adfast Canada Request For Proposal (RFP) ID#2231.pdf
Download: download sample
File size:14'056 bytes
First seen:2024-10-09 13:33:54 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:g3QLtJHaPcfoZ5b43/kl26vOkoTqdhz0c:AQh4UfoZ5bU/Emkooh5
TLSH T144526C880D0EDA6BCACD4E331D28721D618380C19A4F0DB53D5DCAFA5F08B195E8AEE5
Magika pdf
Reporter draymond
Tags:pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
371
Origin country :
CA CA
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  10/10
Confidence:
100%
Tags:
phishing
Gathering data
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
20 / 100
Signature
AI detected landing page (webpage, office document or email)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1529980 Sample: Adfast Canada Request For P... Startdate: 09/10/2024 Architecture: WINDOWS Score: 20 14 x1.i.lencr.org 2->14 16 bg.microsoft.map.fastly.net 2->16 18 AI detected landing page (webpage, office document or email) 2->18 8 Acrobat.exe 18 64 2->8         started        signatures3 process4 process5 10 AcroCEF.exe 107 8->10         started        process6 12 AcroCEF.exe 4 10->12         started       
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2024-10-08 16:51:34 UTC
File Type:
Document
Extracted files:
10
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments