MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3aedbd6383755a4bc090e9ed1d2a093381cba46930aeb5b6cd2f55f75dea7ca7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 16


Maldoc score: 5


Intelligence 16 IOCs YARA 10 File information Comments

SHA256 hash: 3aedbd6383755a4bc090e9ed1d2a093381cba46930aeb5b6cd2f55f75dea7ca7
SHA3-384 hash: a52dda79024da40e65ca652f16fe42f9072f023be3d9a9cb12d8863a65ac32d41318dae1a1cae9e28b054d12b04512c8
SHA1 hash: 48b26143a4fe152f95dad553e5a00c4c8299f970
MD5 hash: 24c8aac04ab5a223da6fe890e07abb91
humanhash: video-happy-bravo-connecticut
File name:Awb_delivery_document_receipt_payment_.docx
Download: download sample
File size:249'102 bytes
First seen:2025-08-27 07:13:53 UTC
Last seen:Never
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 6144:kxiwyN8qs167ccs0SQkX8aSJu3Iyr+swFnjqBaBAoj:bYKccwQW8hu3EAoj
TLSH T1F13412E7924B110FE5B9293BAA094C4EC71131039FC2090232BA795A8FF89DDDE1F61D
TrID 52.2% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
38.8% (.ZIP) Open Packaging Conventions container (17500/1/4)
8.8% (.ZIP) ZIP compressed archive (4000/1)
Magika docx
Reporter lowmal3
Tags:doc

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 5
File Format is MS Word 2007+
Container Format is OpenXML
Office document contains 1 external relationships (see links below)
RelationshipExternal Link
attachedTemplate https://yamantap.me/lAvJvh
Embedded Images

MalwareBazaar found the following images embedded in this file:

MD5 hashdc.creator# of relations
1ecf73254879ee440691f4dee5ba12b491974None
OLE dump

MalwareBazaar was able to identify 5 sections in this file using oledump:

Section IDSection sizeSection name
A194 bytesCompObj
A220 bytesOle
A36 bytesObjInfo
A4145880 bytesCONTENTS

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Awb_delivery_document_receipt_payment_.docx
Verdict:
Malicious activity
Analysis date:
2025-08-27 07:17:43 UTC
Tags:
generated-doc cve-2017-11882 exploit

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/msword
Has a screenshot:
False
Contains macros:
False
Verdict:
Malicious
Score:
94.9%
Tags:
office shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Searching for synchronization primitives
DNS request
Creating a window
Creating a file
Connection attempt
Sending a custom TCP request
Connection attempt by exploiting the app vulnerability
Sending a custom TCP request by exploiting the app vulnerability
Launching a process by exploiting the app vulnerability
Result
Verdict:
Malicious
File Type:
OOXML Word File with Embedding Objects
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Verdict:
Malicious
File Type:
docx
First seen:
2025-08-27T02:39:00Z UTC
Last seen:
2025-08-27T02:39:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis.evad.troj
Score:
68 / 100
Signature
AI detected landing page (webpage, office document or email)
Contains an external reference to another file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Suricata IDS alerts for network traffic
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1765966 Sample: Awb_delivery_document_recei... Startdate: 27/08/2025 Architecture: WINDOWS Score: 68 34 zndpq7uw2elr2st9z-forbesbi.siteintercept.qualtrics.com 2->34 36 yamantap.me 2->36 38 36 other IPs or domains 2->38 49 Suricata IDS alerts for network traffic 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 Contains an external reference to another file 2->53 55 2 other signatures 2->55 8 Acrobat.exe 18 120 2->8         started        10 chrome.exe 17 2->10         started        12 WINWORD.EXE 504 109 2->12         started        14 7 other processes 2->14 signatures3 process4 process5 16 AcroCEF.exe 141 8->16         started        18 AdobeCollabSync.exe 8->18         started        20 AdobeCollabSync.exe 8->20         started        22 chrome.exe 10->22         started        25 chrome.exe 10->25         started        27 chrome.exe 6 10->27         started        dnsIp6 29 AcroCEF.exe 16->29         started        32 AdobeCollabSync.exe 18->32         started        40 tracookiepixel.xyz 22->40 43 1.cpm.ak-is2.net 174.137.133.32 WEBAIR-INTERNETUS United States 22->43 45 624 other IPs or domains 22->45 signatures7 57 Performs DNS queries to domains with low reputation 40->57 process8 dnsIp9 47 23.56.162.204 AKAMAI-ASUS United States 29->47
Gathering data
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-08-27 08:51:35 UTC
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
persistence ransomware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Word file doc 3aedbd6383755a4bc090e9ed1d2a093381cba46930aeb5b6cd2f55f75dea7ca7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments