MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 331d17dbe4ee61d8f2c91d7e4af17fb38102003663872223efaa4a15099554d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 331d17dbe4ee61d8f2c91d7e4af17fb38102003663872223efaa4a15099554d7
SHA3-384 hash: af946153cb4be3ec7b36377080ffe5c26879915c91067fa517f30f968df19790010c6acefdb8a738404d4b52938718d7
SHA1 hash: 818bfc1fdb8126b58835e77f13afa9435e883919
MD5 hash: 76e71cf45e99d03a92c8271998a1caee
humanhash: fruit-dakota-friend-angel
File name:iec56w4ibovnb4wc.onion_Library__DPRK__BabyShark__Hamre_re_NK_deterrence_CWIR_19_Nov18.docm.doc.malw
Download: download sample
File size:19'305 bytes
First seen:2020-03-18 21:56:07 UTC
Last seen:Never
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 384:GOdbpFETgn2shKYUEmej0u1/rVsBx/IXorsb2K6w8r3SOQ:GaqgnFcDgj0udOzSJ+w8r3o
TLSH 6F82AF24E751F826C6EAD07DC11E23B3F31D4649D2844C9F6169E3AC8D986AB530B4FD
Reporter ov3rflow1
Tags:malw

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Document-Word.Trojan.Cav
Status:
Malicious
First seen:
2018-11-28 19:24:42 UTC
AV detection:
28 of 45 (62.22%)
Threat level:
  2/5
Verdict:
unknown
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments