🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32f13566e971a0e674407446b5735dbddb05e19dc96fdb57909a4c19f783f346. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WikiLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 32f13566e971a0e674407446b5735dbddb05e19dc96fdb57909a4c19f783f346
SHA3-384 hash: 9cd5070e16c69be8b5e22e72509a1f37124ee88c803bb28789a8bafadaf3875ffe550be009de1787c139e63a9f3f01de
SHA1 hash: fa6f70181846bbef43bd9c728c6bdb48cf9f627d
MD5 hash: 2d36bae3993a9a4f9d95358bc80463fe
humanhash: foxtrot-cardinal-mexico-north
File name:20231218618342.pdf
Download: download sample
Signature WikiLoader
File size:51'327 bytes
First seen:2023-12-18 22:54:49 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:Zc8nioBjyOhKxCkqU/B2m1KNjyyl470rEDax7W7yq0fuHBWHbFm/sYB36xK3OB7G:ZX3BmOhOqqwDjyylL6yqAuHLB3GKQG
TLSH T19233E0ACA6F4182CDC6682AD61023CD76446B82345C1986534FF8ED23F09FE1DA577E7
Reporter proxylife
Tags:pdf WikiLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
562
Origin country :
RO RO
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
5/10
Score Malicious:
5%
Score Benign:
95%
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
72 / 100
Signature
Downloads suspicious files via Chrome
Injects files into Windows application
Suspicious execution chain found
System process connects to network (likely due to code injection or exploit)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected ZipBomb
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1364203 Sample: 20231218618342.pdf Startdate: 18/12/2023 Architecture: WINDOWS Score: 72 54 respostrong.com 2->54 56 cdn.discordapp.com 2->56 76 Yara detected ZipBomb 2->76 78 Downloads suspicious files via Chrome 2->78 80 Suspicious execution chain found 2->80 10 chrome.exe 16 2->10         started        14 Acrobat.exe 20 76 2->14         started        signatures3 process4 dnsIp5 64 192.168.2.4, 138, 443, 49723 unknown unknown 10->64 66 239.255.255.250 unknown Reserved 10->66 42 C:\...\BOL 202312188107923369.zip (copy), Zip 10->42 dropped 44 59191b74-6eb8-44fc-8d8a-d3ea27bfa0d5.tmp, Zip 10->44 dropped 16 unarchiver.exe 4 10->16         started        18 chrome.exe 10->18         started        21 AcroCEF.exe 74 14->21         started        file6 process7 dnsIp8 23 cmd.exe 2 2 16->23         started        25 7za.exe 2 16->25         started        58 respostrong.com 172.67.215.18, 443, 49748, 49754 CLOUDFLARENETUS United States 18->58 60 142.250.189.142, 443, 49766 GOOGLEUS United States 18->60 62 5 other IPs or domains 18->62 27 AcroCEF.exe 2 21->27         started        process9 dnsIp10 30 wscript.exe 3 245 23->30         started        35 conhost.exe 23->35         started        37 conhost.exe 25->37         started        68 23.46.212.24, 443, 49746 AKAMAI-ASUS United States 27->68 process11 dnsIp12 70 cdn.discordapp.com 162.159.133.233, 443, 49755 CLOUDFLARENETUS United States 30->70 46 C:\ProgramData\v5b2\updaterbehaviorgraphUP.exe, PE32+ 30->46 dropped 48 C:\ProgramData\v5b2\plugins\...\mimeTools.dll, PE32+ 30->48 dropped 50 C:\ProgramData\v5b2\...\nppPluginList.dll, PE32+ 30->50 dropped 52 5 other files (1 malicious) 30->52 dropped 72 System process connects to network (likely due to code injection or exploit) 30->72 74 Windows Scripting host queries suspicious COM object (likely to drop second stage) 30->74 39 notepad.exe 30->39         started        file13 signatures14 process15 signatures16 82 Injects files into Windows application 39->82
Threat name:
Document-PDF.Dropper.Heuristic
Status:
Malicious
First seen:
2023-12-18 18:37:58 UTC
File Type:
Document
Extracted files:
5
AV detection:
3 of 37 (8.11%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments