🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27d8767f61cfa06ec93c0ccbfa333b638f335bbb3c391993c4d065366c124a6f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 27d8767f61cfa06ec93c0ccbfa333b638f335bbb3c391993c4d065366c124a6f
SHA3-384 hash: 3012f0d9b69a6fe50dcb3389685bbcb9c1eaa6862a67ddfd18ef0c8a88b7b38c0bd6077c886be2119b12ce8d5940b036
SHA1 hash: 74f3e72e31495493ffabd10a096fafde10b7cac9
MD5 hash: c57eb3276f51a2c20fa50fbfa9aa8fff
humanhash: music-oklahoma-stairway-burger
File name:Order_Sep_2023.pdf
Download: download sample
File size:16'783 bytes
First seen:2023-09-18 13:15:06 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:RxfVsuD4nuVC2GGGGzoTLb1zM7cfZsOvcAQd6aPr:RxGKC2GGGGz8b1zEcjvcRwaz
TLSH T1ED726D68FE3A9015F05A0F7B061C3747D0AE93D1632964BE282D44857C57E24BF2C7E5
Reporter Anonymous
Tags:AgentTesla pdf TUKHAMTASSER

Intelligence


File Origin
# of uploads :
1
# of downloads :
409
Origin country :
DE DE
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
6.4/10
Score Malicious:
64%
Score Benign:
36%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1310033 Sample: Order_Sep_2023.pdf Startdate: 18/09/2023 Architecture: WINDOWS Score: 48 39 Multi AV Scanner detection for submitted file 2->39 7 AcroRd32.exe 62 2->7         started        9 chrome.exe 12 2->9         started        process3 process4 11 chrome.exe 10 7->11         started        14 chrome.exe 7->14         started        16 chrome.exe 9->16         started        dnsIp5 29 192.168.2.1 unknown unknown 11->29 31 239.255.255.250 unknown Reserved 11->31 18 chrome.exe 11->18         started        21 chrome.exe 14->21         started        33 172.217.13.131 GOOGLEUS United States 16->33 35 104.22.70.197 CLOUDFLARENETUS United States 16->35 37 8 other IPs or domains 16->37 process6 dnsIp7 23 clients.l.google.com 172.217.13.110, 443, 49743, 49809 GOOGLEUS United States 18->23 25 172.217.13.129, 443, 49744, 49810 GOOGLEUS United States 18->25 27 6 other IPs or domains 18->27
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-09-18 11:26:14 UTC
File Type:
Document
Extracted files:
9
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

pdf 27d8767f61cfa06ec93c0ccbfa333b638f335bbb3c391993c4d065366c124a6f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments